CVE-2018-20756
EUVD-2018-1329906.02.2019, 17:29
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| modx | modx_revolution | 𝑥 ≤ 2.7.0 |
| modx | modx_revolution | 2.7.0:pl |
𝑥
= Vulnerable software versions