Vulnerability Description
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Modx | Modx Revolution | 2.7.3 |
Related Weaknesses (CWE)
References
- https://github.com/dahua966/Vul_disclose/blob/main/XXE_modxcms.mdExploitThird Party Advisory
- https://github.com/modxcms/revolution/issues/15237PatchThird Party Advisory
- https://github.com/dahua966/Vul_disclose/blob/main/XXE_modxcms.mdExploitThird Party Advisory
- https://github.com/modxcms/revolution/issues/15237PatchThird Party Advisory
FAQ
What is CVE-2020-25911?
CVE-2020-25911 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
How severe is CVE-2020-25911?
CVE-2020-25911 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-25911?
Check the references section above for vendor advisories and patch information. Affected products include: Modx Modx Revolution.