First published: Tue Apr 25 2017(Updated: )
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MODx Revolution | =2.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-8115 is classified as moderate due to potential exposure of sensitive system directory information.
To fix CVE-2017-8115, upgrade MODX Revolution to the latest version where the vulnerability has been patched.
CVE-2017-8115 specifically affects MODX Revolution version 2.5.7.
Yes, CVE-2017-8115 can be exploited by remote attackers to obtain system directory information, which may lead to further attacks.
While CVE-2017-8115 is a specific issue, it's recommended to review other vulnerabilities in similar versions of MODX to ensure overall security.