CVE-2017-1000067

HIGH8.8EPSS 0.55%

MODX Revolution blind SQL injection

Published: 5/17/2022Modified: 4/23/2024
Also known as:GHSA-phhm-6pgm-mxw9

Description

MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (4)