[SOJOBO-ADV-13-02] - MODx 2.2.10 Reflected Cross Site Scripting I. * Information * ================== Name : MODx 2.2.10 Reflected Cross Site Scripting Software : MODx 2.2.10 and possibly below. Vendor Homepage : http://modx.com/ Vulnerability Type : Reflected Cross-Site Scripting Severity : Low (2/5) Advisory Reference : SOJOBO-ADV-13-02 (http://www.enkomio.com/Advisories) Credits: Sojobo dev team Description: A Reflected Cross Site Scripting vulnerability was discovered during the testing of Sojobo, Static Analysis Tool. II. * Details * =============== A) Reflected Cross Site Scripting in findcore.php [Impact: 2/5] In order to exploit this vulnerability the setup folder mustn't be deleted by the administrator during the installation process. This precondition limit the impact of the vulnerability. Follow a trace to reach the vulnerable code. File: \setup\templates\findcore.php 80: