Description
setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path parameter.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2021-2175 Vulnerability (CVE-2021-2175)
Contao Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-10641)
WordPress Plugin Payment Form for PayPal Pro Multiple Cross-Site Scripting Vulnerabilities (1.0.1)
WordPress Plugin Redux Framework Cross-Site Request Forgery (4.1.20)