Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-7320
HistoryMar 30, 2017 - 7:59 a.m.

Code injection

2017-03-3007:59:00
PRIOn knowledge base
www.prio-n.com
6

6.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.0%

setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (cookie quota exhaustion), or conduct HTTP Response Splitting attacks with resultant XSS, via an invalid parameter value.

CPENameOperatorVersion
modx_revolutionle2.5.4

6.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.0%

Related for PRION:CVE-2017-7320