Description
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php will be triggered by every user, when they visit this module.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Customer Area Cross-Site Request Forgery (8.1.3)
Lighttpd Use After Free Vulnerability (CVE-2013-4560)
WordPress 4.0 Multiple Vulnerabilities (4.0)
WordPress Plugin WP-Recall-Registration, Profile, Commerce & More SQL Injection (16.26.5)
MediaWiki Improper Access Control Vulnerability (CVE-2016-6331)