Ulicms · Ulicms · CVE-2019-11398
**Name of the Vulnerable Software and Affected Versions**
UliCMS versions 2019.1 through 2019.2
**Description**
The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the `go` parameter to `admin/index.php`, the `go` parameter to `/admin/index.php?register=register`, or the `error` parameter to `admin/index.php?action=favicon`.
**Recommendations**
For UliCMS version 2019.1, update to a version that contains a fix for this issue.
For UliCMS version 2019.2, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to the `admin/index.php` and `/admin/index.php?register=register` endpoints to minimize the risk of exploitation.
Avoid using the `go` and `error` parameters in the affected API endpoints until the issue is resolved.