Description
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php will be triggered by every user, when they visit this module.
Remediation
References
Related Vulnerabilities
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-13663)
Jenkins Improper Input Validation Vulnerability (CVE-2017-1000401)
MySQL CVE-2019-2626 Vulnerability (CVE-2019-2626)
WordPress Plugin Pressbooks Textbook Cross-Site Scripting (1.2.5)
WordPress Plugin Advanced Custom Fields PRO Information Disclosure (6.0.2)