Description
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php will be triggered by every user, when they visit this module.
Remediation
References
Related Vulnerabilities
WordPress Plugin Plugin:Newsletter 'data' Parameter Information Disclosure (1.5)
Oracle JRE CVE-2012-1723 Vulnerability (CVE-2012-1723)
Joomla! Core 1.7.x Security Bypass (1.7.0 - 1.7.5)
TYPO3 Improper Authentication Vulnerability (CVE-2011-4628)
ownCloud Incorrect Authorization Vulnerability (CVE-2021-35949)