CVE

Id
104141  
CVE No.
CVE-2017-7321  
Status
Candidate  
Description
setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI.  
Phase
Assigned (20170330)  
Votes
None (candidate not yet proposed)  
Comments