Medium severity6.1NVD Advisory· Published Mar 30, 2017· Updated May 13, 2026
CVE-2017-7320
CVE-2017-7320
Description
setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (cookie quota exhaustion), or conduct HTTP Response Splitting attacks with resultant XSS, via an invalid parameter value.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- mazinahmed.net/services/public-reports/ModX%20-%20Responsible%20Disclosure%20-%20January%202017.pdfnvdExploitTechnical DescriptionThird Party Advisory
- www.securityfocus.com/bid/97228nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.