CVE-2017-9070: XSS
Published May 18, 2017
·Updated
In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.
Affected Software
2 affected componentsFixes available
MODx MODX Revolution<=2.5.6
composer/modx/revolution<2.5.7
2.5.7
Remediation
Patch Available
Patch Available
Event History
May 18, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·02:43 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-9070?
CVE-2017-9070 has a moderate severity level due to the potential for XSS attacks.
2
How do I fix CVE-2017-9070?
To fix CVE-2017-9070, upgrade to MODX Revolution version 2.5.7 or higher.
3
Who is affected by CVE-2017-9070?
Users with resource edit permissions in MODX Revolution versions prior to 2.5.7 are affected by CVE-2017-9070.
4
What type of vulnerability is CVE-2017-9070?
CVE-2017-9070 is an XSS vulnerability that allows injection of malicious scripts.
5
When was CVE-2017-9070 discovered?
CVE-2017-9070 was disclosed in April 2017.