{"id":"CVE-2017-1000067","aliases":["GHSA-phhm-6pgm-mxw9"],"url":"https://o3.security/vulnerability/CVE-2017-1000067","summary":"MODX Revolution blind SQL injection","details":"MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.","published":"2017-07-17T13:18:18.127Z","modified":"2026-07-08T05:50:14.287301973Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01109,"percentile":0.62649,"asOf":"2026-07-31"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"modx/revolution","fixedVersion":"2.6.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/modxcms/revolution/blob/9bf1c6cf7bdc12190b404f93ce7798b39c07bc59/core/xpdo/changelog.txt"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:50:14.287301973Z"}}