6.5
CVSSv2

CVE-2018-1000207

Published: 13/07/2018 Updated: 03/10/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content. This attack appear to be exploitable via Web request. This vulnerability appears to have been fixed in commit 06bc94257408f6a575de20ddb955aca505ef6e68.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

modx modx revolution

Vendor Advisories

Check Point Reference: CPAI-2018-2646 Date Published: 7 Jan 2024 Severity: High ...

Exploits

Modx Revolution versions prior to 264 suffer from a remote code execution vulnerability ...