CVE-2020-12704
MEDIUMUliCMS < 2020.2 - Stored Cross-Site Scripting in PageController
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-12704. PoCs published by SunCSR.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in UliCMS 2020.1 via the 'content' parameter in the page editing feature. The PoC includes a crafted HTTP POST request with a malicious script payload.
Description
UliCMS before 2020.2 has PageController stored XSS.
Exploits (1)
exploitdb
WORKING POC
by SunCSR · textwebappsphp
https://www.exploit-db.com/exploits/48244
This exploit demonstrates a stored XSS vulnerability in UliCMS 2020.1 via the 'content' parameter in the page editing feature. The PoC includes a crafted HTTP POST request with a malicious script payload.
Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
UliCMS 2020.1
Auth required
Prerequisites:
Valid admin session cookie · Access to the admin panel
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://en.ulicms.de/aktuelles.html?single=stored-xss-security-flaw-in-pagecontroller-fixed
Scores
CVSS v3
6.1
EPSS
0.0119
EPSS Percentile
63.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
ulicms/ulicms
< 2020.2
Published
May 07, 2020
Tracked Since
Feb 18, 2026