{"id":"GHSA-j8jp-9x42-4pj5","summary":"Unrestricted Upload of File with Dangerous Type in MODX Revolution","details":"MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.","aliases":["CVE-2022-26149"],"modified":"2023-11-08T04:08:53.371407Z","published":"2022-02-27T00:00:14Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-03-11T19:40:15Z","nvd_published_at":"2022-02-26T21:15:00Z","cwe_ids":["CWE-434"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-26149"},{"type":"PACKAGE","url":"https://github.com/modxcms/revolution"},{"type":"WEB","url":"https://github.com/sartlabs/0days/blob/main/Modx/Exploit.txt"},{"type":"WEB","url":"http://packetstormsecurity.com/files/171488/MODX-Revolution-2.8.3-pl-Remote-Code-Execution.html"}],"affected":[{"package":{"name":"modx/revolution","ecosystem":"Packagist","purl":"pkg:composer/modx/revolution"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.8.3-pl"}]}],"versions":["v2.7.0-pl","v2.7.1-pl","v2.7.2-pl","v2.7.3-pl","v2.8.0-pl","v2.8.1-pl","v2.8.2-pl","v2.8.3-pl"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-j8jp-9x42-4pj5/GHSA-j8jp-9x42-4pj5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}