CVE-2022-26149

MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
References
Link Resource
https://github.com/sartlabs/0days/blob/main/Modx/Exploit.txt Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:modx:revolution:*:*:*:*:*:*:*:*

Information

Published : 2022-02-26 13:15

Updated : 2022-03-08 09:20


NVD link : CVE-2022-26149

Mitre link : CVE-2022-26149


JSON object : View

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

Advertisement

dedicated server usa

Products Affected

modx

  • revolution