Vulnerabilities > Modx > Modx Revolution > 2.5.5
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-05-18 | CVE-2017-9069 | Unrestricted Upload of File with Dangerous Type vulnerability in Modx Revolution In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess. | 8.8 |
2017-05-18 | CVE-2017-9068 | Cross-site Scripting vulnerability in Modx Revolution In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter. | 6.1 |