First published: Wed Feb 06 2019(Updated: )
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MODx Revolution | <=2.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20758 has a medium severity rating due to its potential for XSS (Cross-Site Scripting) attacks.
To fix CVE-2018-20758, upgrade your MODX Revolution version to at least 2.7.1 or later.
CVE-2018-20758 affects MODX Revolution versions up to 2.7.0.
CVE-2018-20758 allows attackers to execute arbitrary JavaScript in the context of an affected user's session.
There is no recommended workaround for CVE-2018-20758; the best approach is to update to a patched version.