Description
A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Coupon Creator Cross-Site Request Forgery (3.1)
Moodle Improper Authentication Vulnerability (CVE-2021-40693)
WordPress Plugin YITH Maintenance Mode Cross-Site Scripting (1.1.4)
WordPress Plugin Social Media Share Buttons & Social Sharing Icons Cross-Site Scripting (2.1.7)
Drupal Deserialization of Untrusted Data Vulnerability (CVE-2020-28948)