Product: MODX Evolution
Risk: Very High
Severity: Critical
Versions: 1.0.6 and all previous releases
Vulnerabilty Type: Permissions, Privileges, and Access Control; Input Validation; SQL Injection
Report Date: 2012-Nov-26
Fixed Date: 2012-Nov-26
Description
The Forgot Manager Login plugin distributed with all versions of MODX Evolution (and 0.9.x) contains a vulnerability that allows users to gain unauthorized access to the MODX Manager.
Affected Releases
All MODX 0.9.x/Evolution releases prior to and including MODX Evolution 1.0.6 are affected.
Solutions
There are three ways to resolve or mitigate the issue:
- Disable Forgot Manager Login plugin
- Upgrade Forgot Manager Login to version 1.1.4
- Upgrade to MODX Evolution 1.0.7.
NOTE
A special thanks to community member Agel_Nash for reporting the full scope of this issue directly to MODX so a resolution could be made available before details were.
About Jay Gilmore
Jay Gilmore is General Manager at MODX, the company behind the open source MODX CMS and MODX Cloud hosting platform. He's been working with MODX since 2006 and was one of the first five employees when the company formed in 2010. He writes about the web and whatever else catches his attention at jaygilmore.ca.
Learn more about Jay Gilmore.