CVE-2022-26149

MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
References
Link Resource
https://github.com/sartlabs/0days/blob/main/Modx/Exploit.txt Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:modx:revolution:*:*:*:*:*:*:*:*

Information

Published : 2022-02-26 09:15

Updated : 2022-03-08 05:20


NVD link : CVE-2022-26149

Mitre link : CVE-2022-26149

Products Affected
No products.
CWE