Description
A stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
Remediation
References
Related Vulnerabilities
PHP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2017-7963)
WordPress Plugin Photospace Gallery Cross-Site Scripting (2.3.5)
Oracle Database Server CVE-2015-2595 Vulnerability (CVE-2015-2595)
WordPress Plugin Visualizer:Tables and Charts Manager for WordPress Multiple Vulnerabilities (3.3.0)
WordPress Plugin Welcart e-Commerce Multiple Vulnerabilities (1.8.2)