Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-9071

In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 49.9%
CVSS Severity
CVSS v3 Score 4.7
CVSS v2 Score 2.6
Products affected by CVE-2017-9071


Contact Us

Shodan ® - All rights reserved