Dear Ryan, or Opengeek or, persons who can contribute to "Security Notices".
I have a wish to you.
Please announce about SQL Injection problem of old snippets in the "Security Notices".
http://modxcms.com/forums/index.php/board,202.0.html
We repoted it the following;
http://modxcms.com/forums/index.php/topic,24020.0.html
garryn made the patch. But they had side effect.
So Soushi who is Japanese moderator reported about it.
But, Since there was no reply, soushi remade the patch.
They are in the Japanese community.
We announced about it and distributed the patch to Japanese users.
But we recommended so that users do not use old snippets strongly.
We think that "FlexSearchFrom" and "UserComment" would be still used.
Actually, they would be used "
http://modxcms.com/blog.html" and "
http://modxcms.com/" ?
I hope that you announce this vulnerability to all MODx users in the world.
P.S.
I attached the pathces.
*
http://modxcms.com/forums/index.php?action=dlattach;topic=21302.0;attach=7165 (UserComment)
*
http://modxcms.com/forums/index.php?action=dlattach;topic=21302.0;attach=7166 (Flexsearchform)