In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:modx:modx_revolution:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.5.6"
}
]
}