Input Validation Vulnerability in MODX <2.8.9 and <3.2.3
The MODX team shared an Input Validation Vulnerability tonight. Depending on your site's configuration, it may be vulnerable and exploitable with varying results.
Updating immediately to MODX 2.8.9 or MODX 3.2.3 is strongly recommended.
A vulnerability has been identified in MODX Revolution related to
insufficient input validation. On its own, this can allow injection of
arbitrary content into site templates. Depending on site-specific
factors, impact can escalate further, up to and including remote code
execution. The issue has been present for an extended period and was
identified during an internal security review.
We would urge you to take this issue serious and perform updates ASAP.
If applying a full update is not an immediate possibility:
- MODX Cloud users are protected by the MODX Cloud team, who have implemented infrastructure-level safeguards for this issue. Still plan to update, but get some coffee first.
- SiteDash users can, in addition to the remote upgrade, install SiteDash Client v1.9.0 which includes a patch. Update all your sites to Client v1.9.0 here.
We've scaled up SiteDash workers for an expected increase in traffic, but you may still encounter delays if a lot of users start updating their sites at the same time. Just let the update sit in the queue; it will run as soon as possible.
---
As an aside, this is the first time we've considered forcing a Client update to all users at once, so we can protect your sites without needing manual intervention. We opted not to, at least not just yet, in case writing a patch at 3am has caused any oversights, bugs in the release, or otherwise causes issues we haven't foreseen. While the vulnerability is a risk, an overnight remote patch across thousands of sites on various infrastructure and versions, is a risk too.
I am very curious to hear your thoughts. In a case like this, would you want us to push out a fix without your manual intervention? Or is what happens on your sites your business, and your business alone? Drop an email to [email protected] to let me know your thoughts.
We've recently disabled comments as we don't care for Disqus's ads and don't use it enough to warrant a subscription. We may implement another commenting system soon. If you have any questions or comments, please feel free to send us an email! We're always excited to hear from you.