CVE-2018-20756
06.02.2019, 17:29
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
Vendor | Product | Version |
---|---|---|
modx | modx_revolution | 𝑥 ≤ 2.7.0 |
modx | modx_revolution | 2.7.0:pl |
𝑥
= Vulnerable software versions