Description
setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI.
Remediation
References
Related Vulnerabilities
XWikiplatform Relative Path Traversal Vulnerability (CVE-2025-55748)
WordPress Plugin HTML5 Video Player-Best WordPress Video Player and Block SQL Injection (2.5.26)
WordPress Plugin WordPress Download Manager Arbitrary File Upload (2.8.97)
SharePoint CVE-2020-17115 Vulnerability (CVE-2020-17115)
Apache HTTP Server Out-of-bounds Read Vulnerability (CVE-2018-1303)