Description
A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
Remediation
References
Related Vulnerabilities
MongoDb Integer Overflow or Wraparound Vulnerability (CVE-2019-2392)
WordPress Plugin BackUpWordPress Remote File Inclusion (0.4.2b)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Cross-Site Scripting (1.5.73)
ownCloud Other Vulnerability (CVE-2012-5609)
Oracle Database Server CVE-2014-6544 Vulnerability (CVE-2014-6544)