CVE-2020-25911

CRITICAL9.1EPSS 0.96%

XML External Entity vulnerability in MODX CMS

Published: 11/1/2021Modified: 12/6/2023
Also known as:GHSA-vhfp-9wvj-gwvgBIT-modx-2020-25911

Description

A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

References (6)