Stored Cross-Site Scripting Vulnerability in Rukovoditel by Rukovoditel
CVE-2022-43166

5.4MEDIUM

Key Information:

Vendor
CVE Published:
28 October 2022

What is CVE-2022-43166?

A stored cross-site scripting vulnerability exists in the Global Entities feature of Rukovoditel v3.2.1. This flaw enables authenticated attackers to inject malicious scripts through the Name parameter when creating a new entity. Proper validation and sanitization mechanisms are compromised, allowing the execution of arbitrary web scripts or HTML upon manipulation. Organizations using this version should implement appropriate defenses against XSS to safeguard user data and maintain application integrity.

References

EPSS Score

6% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.