Stored Cross-Site Scripting Vulnerability in Rukovoditel by anhDQ
CVE-2022-43164
5.4MEDIUM
What is CVE-2022-43164?
The vulnerability in Rukovoditel v3.2.1 exists in the Global Lists feature, specifically for the Name parameter in the /index.php?module=global_lists/lists endpoint. Authenticated attackers can exploit this weakness by injecting a specially crafted payload, potentially allowing for the execution of arbitrary web scripts or HTML within the context of a user's session. This can lead to various malicious activities, including data theft and session hijacking.
