Lucene search

K
cvelistMitreCVELIST:CVE-2017-7320
HistoryMar 30, 2017 - 7:00 a.m.

CVE-2017-7320

2017-03-3007:00:00
mitre
www.cve.org
1

6.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.0%

setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (cookie quota exhaustion), or conduct HTTP Response Splitting attacks with resultant XSS, via an invalid parameter value.

6.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.0%

Related for CVELIST:CVE-2017-7320