Description
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.
Remediation
References
Related Vulnerabilities
Grafana Insufficiently Protected Credentials Vulnerability (CVE-2019-15635)
WordPress 5.5.x Multiple Vulnerabilities (5.5 - 5.5.7)
WordPress Plugin Limit Attempts by BestWebSoft Multiple Vulnerabilities (1.0.3)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-0113)