peter bassill · operator
$ cve CVE-2008-7242 JSON

CVE-2008-7242 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 1.5% (pctl 74)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) messagesubject, and (4) messagebody parameters to certain pages as reachable from manager/index.php; (5) highlight, (6) id, (7) email, (8) name, and (9) parent parameters to index.php; and the (10) docgrp and (11) moreResultsPage parameters to index-ajax.php.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS1.51% — more likely to be exploited than 74% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2009-09-17
Last modified2026-06-16

Affected (1)

VendorProduct
modxcmsmodxcms

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD