Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6306 | MODX allows cross-site scripting (XSS) via an SVG file |
Github GHSA |
GHSA-hm54-fg2w-2g6j | MODX allows cross-site scripting (XSS) via an SVG file |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/rtnthakur/CVE/blob/main/MODX/README.md |
|
Sun, 13 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 04 Apr 2025 02:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Modx
Modx modx |
|
| CPEs | cpe:2.3:a:modx:modx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Modx
Modx modx |
Thu, 20 Mar 2025 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 14 Mar 2025 01:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-19T14:53:43.217Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28010
Updated: 2025-03-19T14:53:05.314Z
Status : Analyzed
Published: 2025-03-13T16:15:27.690
Modified: 2025-04-03T16:42:46.520
Link: CVE-2025-28010
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA