A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/rtnthakur/CVE/blob/main/MODX/README.md |
![]() ![]() |
History
Wed, 19 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Thu, 13 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-13T00:00:00.000Z
Updated: 2025-03-19T14:53:43.217Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28010

Updated: 2025-03-19T14:53:05.314Z

Status : Awaiting Analysis
Published: 2025-03-13T16:15:27.690
Modified: 2025-03-19T15:15:54.430
Link: CVE-2025-28010

No data.