Description Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save. Remediation References CVE-2024-34469 Related Vulnerabilities SharePoint CVE-2022-44690 Vulnerability (CVE-2022-44690) phpMyFAQ Incorrect Authorization Vulnerability (CVE-2024-22208) WordPress Plugin Moova for WooCommerce Cross-Site Scripting (3.5) WordPress Other Vulnerability (CVE-2007-0109) WordPress 5.4.x Multiple Vulnerabilities (5.4 - 5.4.14) Severity High Classification CVE-2024-34469 CWE-707 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L Tags Missing Update Known Vulnerabilities