Description
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php will be triggered by every user, when they visit this module.
Remediation
References
Related Vulnerabilities
Apache Tomcat Other Vulnerability (CVE-2006-7195)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1509)
Python CVE-2023-6507 Vulnerability (CVE-2023-6507)
Joomla! Core 3.6.0 Cross-Site Request Forgery (3.6.0)
IBM RTC Files or Directories Accessible to External Parties Vulnerability (CVE-2017-1602)