A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
History

Thu, 03 Apr 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Modx
Modx modx
CPEs cpe:2.3:a:modx:modx:*:*:*:*:*:*:*:*
Vendors & Products Modx
Modx modx

Wed, 19 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Description A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-19T14:53:43.217Z

Reserved: 2025-03-11T00:00:00.000Z

Link: CVE-2025-28010

cve-icon Vulnrichment

Updated: 2025-03-19T14:53:05.314Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-13T16:15:27.690

Modified: 2025-04-03T16:42:46.520

Link: CVE-2025-28010

cve-icon Redhat

No data.