6.1
CVSS
📦
filedownload
Vendor: modxcms
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
0
Remote Access
Total CVEs
2
Total Indexed
Avg. EPSS
1.81%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
9.8
CVSS
Blind SQL Injection in filedownload v1.4 wordpress plugin
Severity: CRITICAL
8.2
CVSS
7.5
CVSS
download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.
Severity: HIGH