Description
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.
Remediation
References
Related Vulnerabilities
WordPress Improper Input Validation Vulnerability (CVE-2017-1000600)
MySQL CVE-2019-2533 Vulnerability (CVE-2019-2533)
Internet Information Services Other Vulnerability (CVE-1999-0281)
TYPO3 CVE-2024-25121 Vulnerability (CVE-2024-25121)
Oracle Database Server CVE-2014-6542 Vulnerability (CVE-2014-6542)