MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| modx/revolution(Packagist) | 0 | 2.7.1-pl | N/A |
CVSS Metrics