CVE-2022-26149: Malicious File Upload
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26149?
CVE-2022-26149 is considered critical due to the potential for remote code execution by authenticated attackers.
How do I fix CVE-2022-26149?
To fix CVE-2022-26149, upgrade MODX Revolution to the latest version that is beyond 2.8.3.
Who is affected by CVE-2022-26149?
CVE-2022-26149 affects all installations of MODX Revolution versions up to and including 2.8.3.
What types of attacks can exploit CVE-2022-26149?
CVE-2022-26149 can be exploited by authenticated administrators to upload malicious executable files and execute arbitrary code.
What are the prerequisites for exploiting CVE-2022-26149?
To exploit CVE-2022-26149, an attacker must have authenticated administrator access to the MODX Revolution system.