A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6306 MODX allows cross-site scripting (XSS) via an SVG file
Github GHSA Github GHSA GHSA-hm54-fg2w-2g6j MODX allows cross-site scripting (XSS) via an SVG file
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00036}

epss

{'score': 0.00051}


Thu, 03 Apr 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Modx
Modx modx
CPEs cpe:2.3:a:modx:modx:*:*:*:*:*:*:*:*
Vendors & Products Modx
Modx modx

Wed, 19 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Description A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-19T14:53:43.217Z

Reserved: 2025-03-11T00:00:00.000Z

Link: CVE-2025-28010

cve-icon Vulnrichment

Updated: 2025-03-19T14:53:05.314Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-13T16:15:27.690

Modified: 2025-04-03T16:42:46.520

Link: CVE-2025-28010

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.