Stored Cross-Site Scripting Vulnerability in Rukovoditel by Rukovoditel
CVE-2022-43165
5.4MEDIUM
What is CVE-2022-43165?
A stored XSS vulnerability exists in the Global Variables feature of Rukovoditel v3.2.1, where authenticated attackers can inject malicious scripts via the Value parameter. By exploiting this flaw, attackers can execute arbitrary web scripts or HTML after clicking the 'Create' button, compromising user interactions and potentially leading to broader security impacts.
