CVE-2018-20757
06.02.2019, 17:29
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
| Vendor | Product | Version |
|---|---|---|
| modx | modx_revolution | 𝑥 ≤ 2.7.0 |
| modx | modx_revolution | 2.7.0:pl |
𝑥
= Vulnerable software versions