Quote from: jgrant at Mar 10, 2014, 04:10 PMVersion 2.2.13 is out and it should fix the hole which allows unauthorized entry to a site via contexts. But the SQL injection while getting objects trick still works. I guess they consider this less critical and decided a fix can wait till the 2.3 release. In general I recommend everybody update...
Here there was confusion over the terms due to the release 2.2.13 also closing SQL-injection. In the article on my blog I showed the ability to perform queries with context initialization.
Version 2.2.13 also had a problem with SQL-injection. And both vulnerability and closed one patch. But this patch covers only door in the core/connectors. And then there are doors and third-party applications (components).
I think you just need to be patient and wait for the next version MODX Revolution.
And about the exploit on GitHub - this demo (not working). Could only be used as a prototype for someone :-(
Sorry for my english