CVE-2018-20756: XSS
Published Feb 6, 2019
·Updated
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
Affected Software
3 affected componentsFixes available
MODX MODX Revolution<=2.7.0
MODX MODX Revolution=2.7.0-pl
composer/modx/revolution<2.7.1-pl
2.7.1-pl
Remediation
Patch Available
Event History
Feb 6, 2019
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 14, 2022
Advisory Published
via GitHub·01:36 AM
Data Sourced
via GitHub·01:36 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-20756?
CVE-2018-20756 is considered a medium severity vulnerability due to its potential exploitation via XSS attacks.
2
How do I fix CVE-2018-20756?
To fix CVE-2018-20756, you should upgrade MODX Revolution to version 2.7.1 or later.
3
What impacts does CVE-2018-20756 have on MODX Revolution?
CVE-2018-20756 allows attackers to perform cross-site scripting (XSS) attacks through a document resource.
4
In which versions of MODX Revolution is CVE-2018-20756 present?
CVE-2018-20756 affects MODX Revolution versions up to and including 2.7.0-pl.
5
What actions are vulnerable under CVE-2018-20756?
CVE-2018-20756 is vulnerable during Update actions, Quick Edit actions, and when viewing manager logs.