LiveActive security incident?Get immediate response
CVE Record

CVE-2018-17556: MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.

MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This CVE describes a stored cross-site scripting flaw in MODX Revolution 2.6.5-pl when creating a new Media Source. A malicious stored script could run later in another user’s browser inside the MODX management context. The public bundle does not provide CVSS, affected-version range, patch details, or exploitation evidence.

Executive priority

Prioritize this for MODX sites with multiple manager users, delegated content administration, or sensitive administrative sessions. It is not confirmed as actively exploited, but stored XSS in a CMS can support account compromise and unauthorized site changes.

Technical view

The issue is a stored XSS vulnerability tied to the Create New Media Source action in MODX Revolution v2.6.5-pl. The bundle does not identify the exact field, required privilege level, fixed release, or broader version impact. Treat exposure as MODX manager-side content handling risk until vendor guidance confirms scope.

Likely exposure

Likely exposure is MODX Revolution v2.6.5-pl installations where users can access the manager and create Media Sources. The sources do not confirm whether other versions are affected or whether anonymous users can reach the vulnerable path.

Exploitation context

CISA KEV status is false, and the provided sources do not state active exploitation. Stored XSS normally matters most when an attacker has, or can obtain, access to a role that can save malicious content viewed by higher-privileged users.

Researcher notes

Evidence is sparse: the CVE description and GitHub issue identify MODX Revolution 2.6.5-pl and the Media Source creation action, but not the exact sink, privilege requirement, exploit maturity, CVSS, CWE, or fixed version. Avoid broad version claims without vendor confirmation.

Mitigation direction

  • Check MODX vendor guidance and issue 14094 for confirmed remediation details.
  • Upgrade MODX if vendor release notes identify a fixed version.
  • Restrict manager access to trusted users only.
  • Limit Media Source creation permissions to necessary administrators.
  • Review existing Media Sources for unexpected script-like content.

Validation and detection

  • Inventory MODX installations and confirm any running v2.6.5-pl.
  • Identify roles allowed to create or edit Media Sources.
  • Review recent Media Source create and edit activity in logs.
  • Check stored Media Source records for unexpected HTML or JavaScript-like content.
  • Confirm remediation status against official MODX guidance.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-17556 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.