CVE-2015-6588: XSS
Published Aug 29, 2017
·Updated
Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the QUERYSTRING.
Affected Software
1 affected component
MODx MODX Revolution<=1.9.0
Event History
Aug 29, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6588?
CVE-2015-6588 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-6588?
To fix CVE-2015-6588, you should upgrade to MODX Revolution version 1.9.1 or later.
3
What type of vulnerability is CVE-2015-6588?
CVE-2015-6588 is a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2015-6588?
CVE-2015-6588 affects all versions of MODX Revolution prior to 1.9.1.
5
What can attackers do with CVE-2015-6588?
Attackers can use CVE-2015-6588 to inject arbitrary web scripts or HTML into the application via the QUERY_STRING.