First published: Thu May 18 2017(Updated: )
In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MODx Revolution | <=2.5.6 | |
composer/modx/revolution | <2.5.7 | 2.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9069 is classified as a medium severity vulnerability due to the potential for arbitrary code execution.
To fix CVE-2017-9069, upgrade MODX Revolution to version 2.5.7 or later.
Any user with file upload permissions on MODX Revolution versions prior to 2.5.7 is affected by CVE-2017-9069.
CVE-2017-9069 is an arbitrary code execution vulnerability that exploits file upload functionalities.
Yes, CVE-2017-9069 can be exploited remotely by an attacker who can upload files to the server.