HIGH
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code via a crafted certificate
Published Mar 30, 2017
8.1
HIGHCVSS 3.1
EPSS 1.23%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.