Security Advisory
CVE-2017-9068
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.