Description
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information.
Remediation
References
Related Vulnerabilities
WordPress Plugin NextGEN Gallery-WordPress Gallery Remote Code Execution (2.1.59)
WordPress Plugin Easy2Map Cross-Site Scripting (1.5.5)
ProjectSend Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2017-20101)
MySQL CVE-2023-21976 Vulnerability (CVE-2023-21976)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1509)