Lucene search

K
osvGoogleOSV:CVE-2017-7323
HistoryMar 30, 2017 - 7:59 a.m.

CVE-2017-7323

2017-03-3007:59:00
Google
osv.dev
1

7.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.4%

The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code by leveraging the lack of the HTTPS protection mechanism.

7.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.4%

Related for OSV:CVE-2017-7323