Lucene search

K
osvGoogleOSV:CVE-2017-9071
HistoryMay 18, 2017 - 4:29 p.m.

CVE-2017-9071

2017-05-1816:29:00
Google
osv.dev
4

AI Score

6

Confidence

High

EPSS

0.001

Percentile

45.5%

In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.

AI Score

6

Confidence

High

EPSS

0.001

Percentile

45.5%

Related for OSV:CVE-2017-9071