We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 28215
    • 4,149 Posts
    There has been a reported security vulnerability for MODx Revolution 2.0 beta1 and beta2.

    We have committed a temporary fix until we hit the root of the issue, which is a problem with the modAccessibleObject and Context Policy loading.

    SVN users, to fix this vulnerability, please update to r5505.

    Non-SVN users, please make the changes as illustrated here:
    http://svn.modxcms.com/crucible/changelog/modx/?cs=5501

    and here:
    http://svn.modxcms.com/crucible/changelog/modx/?cs=5505

    Again, MODx recommends that you not use any beta products on shared or public servers without acknowledging the risk of potential undiscovered vulnerabilities. If you do choose to use such products, MODx recommends using a restricted username and/or password that is limited only to the MODx install. This also applies to file and user permissions.

    We apologize for any inconvience this might have caused.
      shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect | github | splittingred.com

    This discussion is closed to further replies. Keep calm and carry on.