Vulnerability Description
In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Modx | Modx Revolution | <= 2.5.6 |
Related Weaknesses (CWE)
References
- https://citadelo.com/en/2017/04/modx-revolution-cms/ExploitPatchThird Party Advisory
- https://github.com/modxcms/revolution/pull/13426PatchVendor Advisory
- https://citadelo.com/en/2017/04/modx-revolution-cms/ExploitPatchThird Party Advisory
- https://github.com/modxcms/revolution/pull/13426PatchVendor Advisory
FAQ
What is CVE-2017-9071?
CVE-2017-9071 is a vulnerability with a CVSS score of 4.7 (MEDIUM). In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such ...
How severe is CVE-2017-9071?
CVE-2017-9071 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9071?
Check the references section above for vendor advisories and patch information. Affected products include: Modx Modx Revolution.