A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/rtnthakur/CVE/blob/main/MODX/README.md |
|
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 03 Apr 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Modx
Modx modx |
|
| CPEs | cpe:2.3:a:modx:modx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Modx
Modx modx |
Wed, 19 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 13 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-03-13T00:00:00.000Z
Updated: 2025-03-19T14:53:43.217Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28010
Updated: 2025-03-19T14:53:05.314Z
Status : Analyzed
Published: 2025-03-13T16:15:27.690
Modified: 2025-04-03T16:42:46.520
Link: CVE-2025-28010
No data.