We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 18270
    • 68 Posts
    We had a security team go over one of our modx sites.

    Please see the attached security report from them. Is this a worry? Are there some escaping issues here? I am not real sure myself but perhaps someone else will know what this report is showing.

    Please see attached samples showing the report details.
      • 18373 ☆ A M B ☆
      • 3,141 Posts
      From quick look at the latest source, that variable is properly sanitized to prevent XSS/CSRF attacks as well. It is used in the reset/activate password functionality and I'm pretty sure it does need to be posted along.

      If your security team has found any actual exploits (the ability to inject a simple string is not immediately a vulnerability), please inform the MODX Security team directly via [email protected].
        Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

        Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.