XSS Vulnerability in UliCMS PackageController Affects Multiple Versions
CVE-2020-12703
6.1MEDIUM
What is CVE-2020-12703?
The XSS vulnerability in UliCMS occurs during the uninstall process of the PackageController, allowing an attacker to inject malicious scripts. When users interact with affected components, this flaw can result in unauthorized actions or data theft. Users of UliCMS versions prior to 2020.2 are encouraged to update their installations to mitigate this risk. For more details, refer to the official UliCMS security announcement.
