Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information.
| Software | From | Fixed in |
|---|---|---|
| modx / modx_revolution | 2.5.7 | 2.5.7.x |