CVE-2017-1000067

MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
VendorProductVersion
modxrevolution
2.0.0
modxrevolution
2.0.0:rc1
modxrevolution
2.0.0:rc2
modxrevolution
2.0.0:rc3
modxrevolution
2.0.1
modxrevolution
2.1.0
modxrevolution
2.1.0:p12
modxrevolution
2.1.1
modxrevolution
2.1.1:p12
modxrevolution
2.1.2
modxrevolution
2.1.3
modxrevolution
2.1.4
modxrevolution
2.1.5
modxrevolution
2.2.0
modxrevolution
2.2.0:rc1
modxrevolution
2.2.0:rc2
modxrevolution
2.2.0:rc3
modxrevolution
2.2.1
modxrevolution
2.2.2
modxrevolution
2.2.3
modxrevolution
2.2.4
modxrevolution
2.2.5
modxrevolution
2.2.6
modxrevolution
2.2.7
modxrevolution
2.2.8
modxrevolution
2.2.9
modxrevolution
2.3.0
modxrevolution
2.3.1
modxrevolution
2.4.0
modxrevolution
2.4.1
modxrevolution
2.5.0
modxrevolution
2.5.1
modxrevolution
2.5.2
modxrevolution
2.5.3
modxrevolution
2.5.4
modxrevolution
2.5.5
modxrevolution
2.5.6
𝑥
= Vulnerable software versions