CVE-2017-7321: Code Injection
Published Mar 30, 2017
·Updated
setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the configkey parameter to the setup/index.php?action=welcome URI.
Affected Software
1 affected component
MODx MODX Revolution<=2.5.4
Event History
Mar 30, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Data Sourced
via NVD·07:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7321?
CVE-2017-7321 is considered critical due to its ability to allow remote code execution.
2
How do I fix CVE-2017-7321?
To fix CVE-2017-7321, update MODX Revolution to a version later than 2.5.4.
3
What software is affected by CVE-2017-7321?
CVE-2017-7321 affects MODX Revolution versions 2.5.4 and earlier.
4
What type of attack does CVE-2017-7321 enable?
CVE-2017-7321 enables remote attackers to execute arbitrary PHP code.
5
How can I mitigate the risks associated with CVE-2017-7321 if I cannot immediately update?
If you cannot update, restrict access to the setup/index.php file to trusted IPs only.