CVE-2017-11744: Modx Revolution
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php will be triggered by every user, when they visit this module.
Affected products
- Modx Modx Revolution: version 2.5.7 only
Published 2017-07-30. Last modified 2026-06-17.