XSS Vulnerability in UliCMS PackageController Affects Multiple Versions
CVE-2020-12703

6.1MEDIUM

Key Information:

Vendor

Ulicms

Status
Vendor
CVE Published:
7 May 2020

What is CVE-2020-12703?

The XSS vulnerability in UliCMS occurs during the uninstall process of the PackageController, allowing an attacker to inject malicious scripts. When users interact with affected components, this flaw can result in unauthorized actions or data theft. Users of UliCMS versions prior to 2020.2 are encouraged to update their installations to mitigate this risk. For more details, refer to the official UliCMS security announcement.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.