Description
setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path parameter.
Remediation
References
Related Vulnerabilities
Microsoft SQL Server CVE-2023-21528 Vulnerability (CVE-2023-21528)
WordPress Plugin Adminer Security Bypass (1.4.5)
WordPress Plugin Content Aware Sidebars-Unlimited Widget Areas Security Bypass (3.8)
Oracle HTTP Server Other Vulnerability (CVE-2020-35166)
Artifactory Improper Authentication Vulnerability (CVE-2023-42662)