Record summary

CVE-2019-11398 has a selected CVSS score of 6.1 (medium); EIP currently links 2 catalogued exploits.

Description

Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the error parameter to admin/index.php?action=favicon.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBUliCMS 2019.2 / 2019.1 - Multiple Cross-Site ScriptingExploitDB exploitby Kağan EĞLENCENot analyzed1 file
ExploitDB

PoC details
ExploitDBUliCMS 2019.1 'Spitting Lama' - Persistent Cross-Site ScriptingExploitDB exploitby Unk9vvNNot analyzed1 file
ExploitDB

PoC details

References

4