MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
{
"nvd_published_at": "2022-02-26T21:15:00Z",
"severity": "HIGH",
"github_reviewed_at": "2022-03-11T19:40:15Z",
"cwe_ids": [
"CWE-434"
],
"github_reviewed": true
}