Description
Stored cross-site scripting (XSS) vulnerability in the Name of application field found in the General Configuration page in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to rukovoditel_2.4.1/install/index.php.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server CVE-2018-2760 Vulnerability (CVE-2018-2760)
Jboss EAP Improper Privilege Management Vulnerability (CVE-2019-14838)
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3231)
WordPress Plugin SMS Alert Order Notifications-WooCommerce Cross-Site Scripting (3.4.6)