Stored Cross-Site Scripting Vulnerability in Rukovoditel by Rukovoditel
CVE-2022-43165

5.4MEDIUM

Key Information:

Vendor
CVE Published:
28 October 2022

What is CVE-2022-43165?

A stored XSS vulnerability exists in the Global Variables feature of Rukovoditel v3.2.1, where authenticated attackers can inject malicious scripts via the Value parameter. By exploiting this flaw, attackers can execute arbitrary web scripts or HTML after clicking the 'Create' button, compromising user interactions and potentially leading to broader security impacts.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.