Description
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content. This attack appear to be exploitable via Web request. This vulnerability appears to have been fixed in commit 06bc94257408f6a575de20ddb955aca505ef6e68.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2022-21968 Vulnerability (CVE-2022-21968)
MySQL CVE-2021-2179 Vulnerability (CVE-2021-2179)
WordPress Plugin Autoship Cloud PHP Object Injection (1.0.13)
WordPress Plugin WP-reCAPTCHA Cross-Site Scripting (3.1.3)
WordPress Plugin Blog2Social:Social Media Auto Post & Scheduler Multiple Vulnerabilities (6.9.9)