AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2008-7242

MEDIUM · CVSS 4.3 EPSS 1.51%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-09-17 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2008-7242
Severity
MEDIUM
CVSS
4.3
EPSS
1.51%

Original Filing — NVD Description

Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) messagesubject, and (4) messagebody parameters to certain pages as reachable from manager/index.php; (5) highlight, (6) id, (7) email, (8) name, and (9) parent parameters to index.php; and the (10) docgrp and (11) moreResultsPage parameters to index-ajax.php.