Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6306 | MODX allows cross-site scripting (XSS) via an SVG file |
Github GHSA |
GHSA-hm54-fg2w-2g6j | MODX allows cross-site scripting (XSS) via an SVG file |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/rtnthakur/CVE/blob/main/MODX/README.md |
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 03 Apr 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Modx
Modx modx |
|
| CPEs | cpe:2.3:a:modx:modx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Modx
Modx modx |
Wed, 19 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 13 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-19T14:53:43.217Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28010
Updated: 2025-03-19T14:53:05.314Z
Status : Analyzed
Published: 2025-03-13T16:15:27.690
Modified: 2025-04-03T16:42:46.520
Link: CVE-2025-28010
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA