Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-9070
HistoryMay 18, 2017 - 4:29 p.m.

Cross site scripting

2017-05-1816:29:00
PRIOn knowledge base
www.prio-n.com
4

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.8%

In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.

CPENameOperatorVersion
modx_revolutionle2.5.6

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.8%

Related for PRION:CVE-2017-9070