Description
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
Remediation
References
Related Vulnerabilities
WordPress Plugin Tutor LMS-eLearning and online course solution Security Bypass (2.6.2)
Apache Traffic Server Resource Management Errors Vulnerability (CVE-2016-5396)
Artifactory Deserialization of Untrusted Data Vulnerability (CVE-2022-0573)
WordPress Plugin PHPFreeChat 'url' Parameter Cross-Site Scripting (0.2.8)