Back to Database
Status published
Medium
CVE-2020-12704
UliCMS before 2020.2 has PageController stored XSS....
Vulnerability Description
UliCMS before 2020.2 has PageController stored XSS.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-12704
Credits & Attribution
No credits recorded in the NVD database.
References
More from ulicms
View All →CVE-2023-53914
UliCMS 2023.1 Authentication Bypass via Mass Assignment Vulnerability
Critical
9.3
CVE-2020-12703
UliCMS before 2020.2 has XSS during PackageController uninstall....
Medium
6.1
CVE-2019-11398
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1...
Medium
6.1
Affected Vendor
ulicms
View all reports →Affected Software
ulicms
Vulnerable Versions:
0
Timeline
Official Publish:
May 7th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.