Description
In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus, an attacker can inject malicious script to steal all users' valuable data.
Remediation
References
Related Vulnerabilities
WordPress Plugin Chained Quiz Cross-Site Scripting (1.1.9)
WordPress Plugin WP Cerber Security, Anti-spam & Malware Scan Cross-Site Request Forgery (2.7.2)
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-32732)
WordPress Plugin WP Cerber Security, Anti-spam & Malware Scan Security Bypass (8.9)
Drupal Reliance on Cookies without Validation and Integrity Checking Vulnerability (CVE-2022-29248)