CVE-2019-1010123
Last modified
CVE-2019-1010123 is a vulnerability of currently unknown severity. MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. The component is: Filtering user parameters before passing them into phpthumb class. The attack vector is: web request via /assets/components/gallery/connector.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Modx | Modx Revolution | <= 2.6.4 |
References
- https://modx.pro/security/15912#comment-99640Exploit, Vendor Advisory
- https://modx.pro/security/15912#comment-99640Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1010123?
How severe is CVE-2019-1010123?
How do I fix CVE-2019-1010123?
Are you affected by CVE-2019-1010123?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
