Stored Cross-Site Scripting Vulnerability in Rukovoditel by Rukovoditel
CVE-2022-43166
5.4MEDIUM
What is CVE-2022-43166?
A stored cross-site scripting vulnerability exists in the Global Entities feature of Rukovoditel v3.2.1. This flaw enables authenticated attackers to inject malicious scripts through the Name parameter when creating a new entity. Proper validation and sanitization mechanisms are compromised, allowing the execution of arbitrary web scripts or HTML upon manipulation. Organizations using this version should implement appropriate defenses against XSS to safeguard user data and maintain application integrity.
