Description
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
Remediation
References
Related Vulnerabilities
WordPress Plugin Real WYSIWYG 'insert_file.php' Arbitrary File Upload (0.0.2)
WordPress Plugin Product Catalog Arbitrary File Upload (3.8.6)
Sqlite NULL Pointer Dereference Vulnerability (CVE-2019-19242)
WordPress Plugin Social Share Icons & Social Share Buttons Cross-Site Scripting (3.0.5)
WordPress Plugin BackWPup Multiple Unspecified Vulnerabilities (3.2.1)