Description
setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI.
Remediation
References
Related Vulnerabilities
MyBB Other Vulnerability (CVE-2010-4628)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-0327)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2016-5096)
WordPress Plugin Quick Contact Form Security Bypass (8.0.1)
Liferay Portal Insecure Default Initialization of Resource Vulnerability (CVE-2024-25610)