Description
A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.
Remediation
References
Related Vulnerabilities
GeoServer Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2024-34711)
Oracle Database Server CVE-2009-1994 Vulnerability (CVE-2009-1994)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-0813)
Drupal Core 9.2.x Security Bypass (9.2.0 - 9.2.17)
WordPress Plugin Grapefile File Sharing 'grapeupload.php' Arbitrary File Upload (1.1)