Vulnerability record · CVE-2018-1000207 · published 13 July 2018
CVE-2018-1000207: MODX Revolution phpthumb parameter filtering flaw allows arbitrary file creation
Modx · Modx Revolution
MODX Revolution 2.6.4 and earlier fails to properly filter user-supplied parameters before passing them into the phpthumb class, allowing an attacker to create files with a chosen filename and content. The flaw is an incorrect access control issue fixed in commit 06bc94257408f6a575de20ddb955aca505ef6e68. Because it enables writing attacker-controlled files on the server, it can lead to code execution or site compromise.
Description
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content. This attack appear to be exploitable via Web request. This vulnerability appears to have been fixed in commit 06bc94257408f6a575de20ddb955aca505ef6e68.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with high EPSS and public exploit references, but exploitation requires high privileges, keeping it below critical.
What it is
MODX Revolution 2.6.4 and earlier fails to properly filter user-supplied parameters before passing them into the phpthumb class, allowing an attacker to create files with a chosen filename and content. The flaw is an incorrect access control issue fixed in commit 06bc94257408f6a575de20ddb955aca505ef6e68. Because it enables writing attacker-controlled files on the server, it can lead to code execution or site compromise.
Impact
An attacker can write arbitrary files with attacker-chosen names and content to the server, which can be used to plant web shells or otherwise take over the application. The CVSS vector indicates high confidentiality, integrity and availability impact.
Attack surface
Reachable over the network via a web request to the phpthumb handling path; the CVSS vector requires high privileges (PR:H) and no user interaction (UI:N).
Exploitation
No CISA KEV listing, but EPSS is very high (0.64088, 99.188th percentile) and public references are tagged Exploit, indicating exploit code is publicly available.
What to do
- Upgrade MODX Revolution to a version containing commit 06bc94257408f6a575de20ddb955aca505ef6e68 or later.
- If immediate upgrade is not possible, restrict access to phpthumb endpoints to trusted authenticated users only.
- Review and harden permissions for accounts that can reach the affected functionality, since exploitation requires high privileges.
- Monitor and restrict write access to web-accessible directories to limit where created files can be placed.
Detection
- Monitor web server logs for requests to phpthumb endpoints with unusual or attacker-controlled filename parameters.
- Alert on creation of new files in web-accessible directories, especially files with script extensions.
- Compare file system contents against known-good baselines to detect unexpected files with custom names or content.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/a2u/CVE-2018-1000207 | Broken LinkThird Party Advisory |
| https://github.com/modxcms/revolution/commit/06bc94257408f6a575de20ddb955aca505ef6e68 | PatchThird Party Advisory |
| https://github.com/modxcms/revolution/pull/13979 | ExploitThird Party Advisory |
| https://rudnkh.me/posts/critical-vulnerability-in-modx-revolution-2-6-4 | ExploitThird Party Advisory |
| https://github.com/a2u/CVE-2018-1000207 | Broken LinkThird Party Advisory |
| https://github.com/modxcms/revolution/commit/06bc94257408f6a575de20ddb955aca505ef6e68 | PatchThird Party Advisory |
| https://github.com/modxcms/revolution/pull/13979 | ExploitThird Party Advisory |
| https://rudnkh.me/posts/critical-vulnerability-in-modx-revolution-2-6-4 | ExploitThird Party Advisory |
Track CVE-2018-1000207 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1000207), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.