PT-2021-10564 · Ukcms · Ukcms

Junerainblog

·

Published

2021-08-12

·

Updated

2022-09-23

·

CVE-2020-20977

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: UK CMS version 1.1.10
Description: A stored cross site scripting (XSS) vulnerability in "index.php/legend/6.html" of UK CMS allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Comments section.
Recommendations: For UK CMS version 1.1.10, consider disabling the Comments section in "index.php/legend/6.html" until a patch is available to prevent exploitation of the stored XSS vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-20977

Affected Products

Ukcms