Description
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text field after clicking "Add".
Remediation
References
Related Vulnerabilities
UAParser.js Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2021-4229)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-40603)
WordPress Plugin Shortcoder-Create Shortcodes for Anything Security Bypass (6.3)
Apache HTTP Server Resource Management Errors Vulnerability (CVE-2007-6423)