CVE-2010-1427: XSS
Published Apr 15, 2010
·Updated
Cross-site scripting (XSS) vulnerability in the SearchHighlight plugin in MODx Evolution before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to AjaxSearch.
Affected Software
9 affected components
Modxcms Evolution<=1.0.2
Modxcms Evolution=0.9.0
Modxcms Evolution=0.9.1
Modxcms Evolution=0.9.2.1
Modxcms Evolution=0.9.5
Modxcms Evolution=0.9.6
Modxcms Evolution=0.9.6.1
Modxcms Evolution=0.9.6.1-p1
Modxcms Evolution=0.9.6.2
Remediation
Patch Available
Patch Available
Event History
Apr 15, 2010
CVE Published
via MITRE·09:12 PM
Data Sourced
via MITRE·09:12 PM
Description
Data Sourced
via NVD·09:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1427?
CVE-2010-1427 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
Which versions of MODx Evolution are affected by CVE-2010-1427?
CVE-2010-1427 affects MODx Evolution versions up to and including 1.0.2 and some specific earlier versions.
3
How do I fix CVE-2010-1427?
To fix CVE-2010-1427, upgrade to MODx Evolution version 1.0.3 or later.
4
What type of attack can be executed through CVE-2010-1427?
CVE-2010-1427 could allow remote attackers to inject arbitrary web scripts or HTML into the application.
5
Is there a workaround for CVE-2010-1427 until I can update?
A suitable workaround for CVE-2010-1427 is not well-documented, but immediately updating the software is recommended.