Description
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
Remediation
References
Related Vulnerabilities
WordPress Plugin My Tickets Security Bypass (1.9.11)
LimeSurvey Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2019-16175)
OpenSSL Improper Input Validation Vulnerability (CVE-2016-6305)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.4)
MySQL Resource Management Errors Vulnerability (CVE-2010-3679)