vendor:
MODX Revolution
by:
Narendra Bhati
9
CVSS
CRITICAL
CSRF Tokens Bypass + Reflected Cross Site Scripting + Stored XSS
CWE
Product Name: MODX Revolution
Affected Version From: 2.0.0
Affected Version To: 2.2.14
Patch Exists: NO
Related CWE: Requested
CPE:
Platforms Tested:
2014
MODX Revolution CSRF Tokens Bypass + Reflected Cross Site Scripting + Stored XSS
The vulnerability allows an attacker to perform Cross-Site Scripting (XSS) attacks and bypass CSRF Tokens Protection. This can lead to various malicious activities such as taking over victim accounts, changing primary email addresses, sending forged requests, and tricking admins to attack their own users.
Mitigation:
Upgrade to MODX Revolution 2.2.15.