Total vulnerabilities in the database
In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.
Software | From | Fixed in |
---|---|---|
modx / modx_revolution | - | 2.5.6.x |