Description
A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Value parameter after clicking "Create".
Remediation
References
Related Vulnerabilities
Apache Tomcat Improper Encoding or Escaping of Output Vulnerability (CVE-2022-45143)
WordPress Plugin SupportFlow Multiple Cross-Site Scripting Vulnerabilities (0.6)
WordPress Plugin Database Backup for WordPress 'edit.php' Directory Traversal (1.7)
WordPress Plugin BulletProof Security Cross-Site Scripting (.52.4)