GHSA-m899-6mh4-mpc5
Dashboard / Vulnerabilities / GHSA-m899-6mh4-mpc5
Summary: MODX Revolution Incorrect Access Control vulnerability
Details: MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content. This attack appear to be exploitable via Web request. This vulnerability appears to have been fixed in commit 06bc94257408f6a575de20ddb955aca505ef6e68.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1000207, https://github.com/modxcms/revolution/pull/13979, https://github.com/modxcms/revolution/commit/06bc94257408f6a575de20ddb955aca505ef6e68, https://github.com/a2u/CVE-2018-1000207, https://github.com/modxcms/revolution, https://rudnkh.me/posts/critical-vulnerability-in-modx-revolution-2-6-4
Affected packages
Package
Name: modx/revolution
Purl: pkg:composer/modx/revolution
Affected ranges
Type: ECOSYSTEM
Events:
