CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable.
CVE
CVE-2017-7321
Severity
CRITICAL
CVSS
9.8
EPSS
2.15%
Original NVD Description
setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI.
Related CVEs
Other vulnerabilities affecting the same vendor(s)