← Back to CVE List

CVE-2017-9071

Published: 2017-05-18T16:29Z
Last Modified: 2024-11-21T03:35Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt