CVE-2018-1000207
Dashboard / Vulnerabilities / CVE-2018-1000207
Summary:
Details: MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content. This attack appear to be exploitable via Web request. This vulnerability appears to have been fixed in commit 06bc94257408f6a575de20ddb955aca505ef6e68.
References: https://github.com/modxcms/revolution/commit/06bc94257408f6a575de20ddb955aca505ef6e68, https://github.com/a2u/CVE-2018-1000207, https://github.com/modxcms/revolution/pull/13979, https://rudnkh.me/posts/critical-vulnerability-in-modx-revolution-2-6-4
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 0
Fixed -None
Affected versions
v2.6.4-pl
v2.6.3-pl
v2.6.2-pl
v2.6.1-pl
v2.6.0-pl
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
