<![CDATA[ MODX Evolution 1.0.13 (and prior) AjaxSearch Vulnerability - My Forums]]> https://forums.modx.com/thread/?thread=91266 <![CDATA[Re: MODX Evolution 1.0.13 (and prior) AjaxSearch Vulnerability]]> https://forums.modx.com/thread/91266/modx-evolution-1-0-13-and-prior-ajaxsearch-vulnerability#dis-post-499837 matdave Jun 09, 2014, 11:36 AM https://forums.modx.com/thread/91266/modx-evolution-1-0-13-and-prior-ajaxsearch-vulnerability#dis-post-499837 <![CDATA[MODX Evolution 1.0.13 (and prior) AjaxSearch Vulnerability]]> https://forums.modx.com/thread/91266/modx-evolution-1-0-13-and-prior-ajaxsearch-vulnerability#dis-post-499547 Product: MODX Evolution
Risk: Very High
Severity: Critical
Versions: <=1.0.13
Vulnerabilty Type: Remote Code Execution
Report Date: 2014-May-29
Fixed Date: 2014-June-5

Description
The AjaxSearch component distributed with all versions of MODX Evolution (and 0.9.x) contains a vulnerability that allows remote code execution.

Affected Releases
All MODX 0.9.x/Evolution releases prior to and including MODX Evolution 1.0.13 (with AjaxSearch installed) are affected.

Solutions
There are two ways to resolve or mitigate the issue:

  1. Upgrade AjaxSearch to version 1.10.1
  2. Upgrade to MODX Evolution 1.0.14.

NOTE
A special thanks to Semko Vitaliy for identifying the vector and community member Thomas Jakobi for the resolution.]]>
opengeek Jun 05, 2014, 04:00 PM https://forums.modx.com/thread/91266/modx-evolution-1-0-13-and-prior-ajaxsearch-vulnerability#dis-post-499547