Description
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php will be triggered by every user, when they visit this module.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Cross-Site Scripting (3.0.0 - 3.9.15)
Sqlite Improper Validation of Array Index Vulnerability (CVE-2022-35737)
Drupal Core 7.x Multiple Vulnerabilities (7.0 - 7.51)
WordPress Plugin Dean's Permalinks Migration Cross-Site Request Forgery (1.0)
WordPress Plugin Pro Quoter Multiple Cross-Site Scripting Vulnerabilities (1.0)