Description
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.
Remediation
References
Related Vulnerabilities
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-0191)
e107 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-1989)
WordPress Plugin Thrive Optimize Security Bypass (1.4.13.2)
WordPress 1.5.1.2 Multiple Vulnerabilities (1.0 - 1.5.1.2)
OpenSSL Resource Management Errors Vulnerability (CVE-2012-1165)