We had a security team go over one of our modx sites.
Please see the attached security report from them. Is this a worry? Are there some escaping issues here? I am not real sure myself but perhaps someone else will know what this report is showing.
Please see attached samples showing the report details.
-
☆ A M B ☆
- 3,141 Posts
From quick look at the latest source, that variable is properly sanitized to prevent XSS/CSRF attacks as well. It is used in the reset/activate password functionality and I'm pretty sure it does need to be posted along.
If your security team has found any actual exploits (the ability to inject a simple string is not immediately a vulnerability), please inform the MODX Security team directly via
[email protected].