Description
setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Multiple Vulnerabilities (3.2.0 - 3.6.5)
MySQL CVE-2019-2997 Vulnerability (CVE-2019-2997)
WordPress 3.8.x Cross-Domain Flash Injection Vulnerability (3.8 - 3.8.24)
MySQL CVE-2017-3529 Vulnerability (CVE-2017-3529)
WordPress Plugin Edwiser Bridge-WordPress Moodle LMS Integration Unspecified Vulnerability (2.0.7)