First published: Sun Oct 31 2021(Updated: )
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MODx Revolution | =2.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-25911 is classified as medium due to its potential for information disclosure and denial of service.
To fix CVE-2020-25911, upgrade to a later version of MODX CMS that addresses the XML External Entity vulnerability.
CVE-2020-25911 is caused by improper handling of XML input in the modRestServiceRequest component of MODX CMS.
An attacker exploiting CVE-2020-25911 can potentially disclose sensitive information or cause denial of service.
MODX CMS version 2.7.3 is not safe to use due to the presence of CVE-2020-25911, and users should upgrade to mitigate the risk.