CVE-2018-1000207 is an Incorrect Access Control vulnerability affecting MODX Revolution versions up to 2.6.4. This flaw allows a highly privileged attacker to create files with custom filenames and content via a web request, due to insufficient filtering of user parameters passed to the phpthumb class. Rated with a CVSS score of 7.2 (High), it poses a significant risk to confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, the vulnerability has been patched in commit 06bc94257408f6a575de20ddb955aca505ef6e68.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.4CPE matchmatch criteria | cpe:2.3:a:modx:modx_revolution:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.