Description
MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result in remove files. This attack appear to be exploitable via web request via security/login processor. This vulnerability appears to have been fixed in pull 13980.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Edit Unspecified Vulnerability (3.0)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-14630)
WordPress Plugin WP Support Plus Responsive Ticket System Unspecified Vulnerability (8.0.7)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-5625)