Security readout for executives and security teams
Plain-English summary
This CVE describes a stored cross-site scripting flaw in MODX Revolution 2.6.5-pl when creating a new Media Source. A malicious stored script could run later in another user’s browser inside the MODX management context. The public bundle does not provide CVSS, affected-version range, patch details, or exploitation evidence.
Executive priority
Prioritize this for MODX sites with multiple manager users, delegated content administration, or sensitive administrative sessions. It is not confirmed as actively exploited, but stored XSS in a CMS can support account compromise and unauthorized site changes.
Technical view
The issue is a stored XSS vulnerability tied to the Create New Media Source action in MODX Revolution v2.6.5-pl. The bundle does not identify the exact field, required privilege level, fixed release, or broader version impact. Treat exposure as MODX manager-side content handling risk until vendor guidance confirms scope.
Likely exposure
Likely exposure is MODX Revolution v2.6.5-pl installations where users can access the manager and create Media Sources. The sources do not confirm whether other versions are affected or whether anonymous users can reach the vulnerable path.
Exploitation context
CISA KEV status is false, and the provided sources do not state active exploitation. Stored XSS normally matters most when an attacker has, or can obtain, access to a role that can save malicious content viewed by higher-privileged users.
Researcher notes
Evidence is sparse: the CVE description and GitHub issue identify MODX Revolution 2.6.5-pl and the Media Source creation action, but not the exact sink, privilege requirement, exploit maturity, CVSS, CWE, or fixed version. Avoid broad version claims without vendor confirmation.
Mitigation direction
- Check MODX vendor guidance and issue 14094 for confirmed remediation details.
- Upgrade MODX if vendor release notes identify a fixed version.
- Restrict manager access to trusted users only.
- Limit Media Source creation permissions to necessary administrators.
- Review existing Media Sources for unexpected script-like content.
Validation and detection
- Inventory MODX installations and confirm any running v2.6.5-pl.
- Identify roles allowed to create or edit Media Sources.
- Review recent Media Source create and edit activity in logs.
- Check stored Media Source records for unexpected HTML or JavaScript-like content.
- Confirm remediation status against official MODX guidance.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-17556 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/modxcms/revolution/issues/14094CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
