CVE-2017-9067

HIGH7.0EPSS 0.21%

MODX Revolution Directory Traversal Vulnerability

Published: 5/17/2022Modified: 4/22/2025
Also known as:GHSA-cgrv-6h2h-6f7v

Description

In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.0CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

References (5)