MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4775 | MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges. |
Github GHSA |
GHSA-phhm-6pgm-mxw9 | MODX Revolution blind SQL injection |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:53:06.137Z
Reserved: 2017-07-10T00:00:00.000Z
Link: CVE-2017-1000067
No data.
Status : Deferred
Published: 2017-07-17T13:18:18.127
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-1000067
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA