6.1
CVSSv3

CVE-2019-11398

Published: 08/05/2019 Updated: 10/06/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote malicious users to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the error parameter to admin/index.php?action=favicon.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ulicms ulicms 2019.2

ulicms ulicms 2019.1

Exploits

# Exploit Title: UliCMS - 20192 , 20191 - Multiple Cross-Site Scripting # Google Dork: intext:"by UliCMS" # Exploit Author: Kağan EĞLENCE # Vendor Homepage: enulicmsde/ # Version: 20192 , 20191 # CVE : CVE-2019-11398 ### Vulnerability 1 Url : localhost/ulicms/ulicms/admin/indexphp?go=test%27%20accesskey=%27X%27%20onclick=% ...
# Exploit Title: UliCMS 20191 "Spitting Lama" - Stored Cross-Site Scripting # Google Dork: intext:"by UliCMS" # Date: 2019-05-12 # Exploit Author: Unk9vvN # Vendor Homepage: enulicmsde # Software Link: wwwulicmsde/aktuelleshtml?single=ulicms-20191-spitting-lama-ist-fertig # Version: 20191 # Tested on: Kali Linux # CVE : CVE-2 ...
UliCMS version2 0191 suffers from a persistent cross site scripting vulnerability ...
UliCMS versions 20192 and 20191 suffers from multiple cross site scripting vulnerabilities ...