MODX Evolution 1.0.13 (and prior) AjaxSearch Vulnerability

By Jason Coward  |  June 5, 2014  |  1 min read
MODX Evolution 1.0.13 (and prior) AjaxSearch Vulnerability

Product: MODX Evolution
Risk: Very High
Severity: Critical
Versions: <=1.0.13
Vulnerabilty Type: Remote Code Execution
Report Date: 2014-May-29
Fixed Date: 2014-June-5

Description
The AjaxSearch component distributed with all versions of MODX Evolution (and 0.9.x) contains a vulnerability that allows remote code execution.

Affected Releases
All MODX 0.9.x/Evolution releases prior to and including MODX Evolution 1.0.13 (with AjaxSearch installed) are affected.

Solutions
There are two ways to resolve or mitigate the issue:


  1. Upgrade AjaxSearch to version 1.10.1
  2. Upgrade to MODX Evolution 1.0.14.


NOTE
A special thanks to Semko Vitaliy for identifying the vector and community member Thomas Jakobi for the resolution.


About Jason Coward

Jason Coward is a co-founder of MODX and its Chief Architect. He is the author of xPDO and lead architect of MODX Revolution. Find more of his writing at opengeek.com or follow him on GitHub.

Learn more about Jason Coward.