MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
| Software | From | Fixed in |
|---|---|---|
| modx / modx_revolution | - | 2.7.0.x |
| modx / modx_revolution | 2.7.0-pl | 2.7.0-pl.x |