← Vulnerability feed

Vulnerability record · CVE-2018-1000207 · published 13 July 2018

CVE-2018-1000207: MODX Revolution phpthumb parameter filtering flaw allows arbitrary file creation

Modx · Modx Revolution

MODX Revolution 2.6.4 and earlier fails to properly filter user-supplied parameters before passing them into the phpthumb class, allowing an attacker to create files with a chosen filename and content. The flaw is an incorrect access control issue fixed in commit 06bc94257408f6a575de20ddb955aca505ef6e68. Because it enables writing attacker-controlled files on the server, it can lead to code execution or site compromise.

7.2 CVSS 3.0 High EPSS 64% · top 0.8% CWE-732 · Incorrect permission assignment
7.2CVSS 3.0 base score, v2 6.5
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content. This attack appear to be exploitable via Web request. This vulnerability appears to have been fixed in commit 06bc94257408f6a575de20ddb955aca505ef6e68.

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 7.2 with high EPSS and public exploit references, but exploitation requires high privileges, keeping it below critical.

What it is

MODX Revolution 2.6.4 and earlier fails to properly filter user-supplied parameters before passing them into the phpthumb class, allowing an attacker to create files with a chosen filename and content. The flaw is an incorrect access control issue fixed in commit 06bc94257408f6a575de20ddb955aca505ef6e68. Because it enables writing attacker-controlled files on the server, it can lead to code execution or site compromise.

Impact

An attacker can write arbitrary files with attacker-chosen names and content to the server, which can be used to plant web shells or otherwise take over the application. The CVSS vector indicates high confidentiality, integrity and availability impact.

Attack surface

Reachable over the network via a web request to the phpthumb handling path; the CVSS vector requires high privileges (PR:H) and no user interaction (UI:N).

Exploitation

No CISA KEV listing, but EPSS is very high (0.64088, 99.188th percentile) and public references are tagged Exploit, indicating exploit code is publicly available.

What to do

  • Upgrade MODX Revolution to a version containing commit 06bc94257408f6a575de20ddb955aca505ef6e68 or later.
  • If immediate upgrade is not possible, restrict access to phpthumb endpoints to trusted authenticated users only.
  • Review and harden permissions for accounts that can reach the affected functionality, since exploitation requires high privileges.
  • Monitor and restrict write access to web-accessible directories to limit where created files can be placed.

Detection

  • Monitor web server logs for requests to phpthumb endpoints with unusual or attacker-controlled filename parameters.
  • Alert on creation of new files in web-accessible directories, especially files with script extensions.
  • Compare file system contents against known-good baselines to detect unexpected files with custom names or content.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1000207 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7321Modx revolution code injection vulnerabilitysetup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parame…EPSS 2.2%9.8CVE-2017-7324Modx revolution code injection vulnerabilitysetup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path paramete…EPSS 2.2%9.1CVE-2020-25911Modx revolution xml external entity (xxe) vulnerabilityA XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information di…EPSS 2.4%8.8CVE-2017-9069Modx revolution unrestricted file upload vulnerabilityIn MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.EPSS 1.9%8.1CVE-2017-7322Modx revolution improper certificate validation vulnerabilityThe (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which…EPSS 1.2%8.1CVE-2017-7323Modx revolution vulnerabilityThe (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in…EPSS 2.1%7.5CVE-2019-1010123Modx revolution unrestricted file upload vulnerabilityMODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a fi…EPSS 1.2%7.5CVE-2018-1000208Modx revolution path traversal vulnerabilityMODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result in remov…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2018-1000207), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.