CVE-2017-9067
HIGH7.0EPSS 0.21%MODX Revolution Directory Traversal Vulnerability
Published: 5/17/2022Modified: 4/22/2025
Also known as:GHSA-cgrv-6h2h-6f7v
Description
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.
Affected packages (1)
- Packagist/modx/revolutionfrom 0, < 2.5.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.0 | CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |