CVE-2017-1000067

EUVD-2022-4775
MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
Affected Products (NVD)
VendorProductVersion
modxrevolution
2.0.0
modxrevolution
2.0.0:rc1
modxrevolution
2.0.0:rc2
modxrevolution
2.0.0:rc3
modxrevolution
2.0.1
modxrevolution
2.1.0
modxrevolution
2.1.0:p12
modxrevolution
2.1.1
modxrevolution
2.1.1:p12
modxrevolution
2.1.2
modxrevolution
2.1.3
modxrevolution
2.1.4
modxrevolution
2.1.5
modxrevolution
2.2.0
modxrevolution
2.2.0:rc1
modxrevolution
2.2.0:rc2
modxrevolution
2.2.0:rc3
modxrevolution
2.2.1
modxrevolution
2.2.2
modxrevolution
2.2.3
modxrevolution
2.2.4
modxrevolution
2.2.5
modxrevolution
2.2.6
modxrevolution
2.2.7
modxrevolution
2.2.8
modxrevolution
2.2.9
modxrevolution
2.3.0
modxrevolution
2.3.1
modxrevolution
2.4.0
modxrevolution
2.4.1
modxrevolution
2.5.0
modxrevolution
2.5.1
modxrevolution
2.5.2
modxrevolution
2.5.3
modxrevolution
2.5.4
modxrevolution
2.5.5
modxrevolution
2.5.6
𝑥
= Vulnerable software versions