HIGH
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code by leveraging the lack of the HTTPS protection mechanism
Published Mar 30, 2017
8.1
HIGHCVSS 3.1
EPSS 2.09%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.