Description
A stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Product Subtitle For WooCommerce Arbitrary File Disclosure (4.1)
WordPress Plugin Support Ticket System By Phoeniixx Unspecified Vulnerability (2.7)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3092)
WordPress Plugin All-in-One WP Migration Security Bypass (2.0.4)