CVE-2017-7322: High severity MODx MODX Revolution vulnerability
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7322?
CVE-2017-7322 is classified as a critical vulnerability due to the potential for man-in-the-middle attacks and arbitrary code execution.
How do I fix CVE-2017-7322?
To fix CVE-2017-7322, update to a version of MODX Revolution later than 2.5.4-pl that properly verifies X.509 certificates.
What software versions are affected by CVE-2017-7322?
MODX Revolution versions up to and including 2.5.4-pl are affected by CVE-2017-7322.
What type of attack is possible due to CVE-2017-7322?
CVE-2017-7322 allows man-in-the-middle attackers to spoof servers and execute arbitrary code.
Is there a patch available for CVE-2017-7322?
Yes, users should upgrade to a fixed version of MODX Revolution to mitigate CVE-2017-7322.