Stored Cross-Site Scripting Vulnerability in Rukovoditel
CVE-2022-43185
5.4MEDIUM
What is CVE-2022-43185?
A stored cross-site scripting (XSS) vulnerability exists in the Configuration/Holidays module of Rukovoditel version 3.2.1. This security flaw enables attackers to inject and execute arbitrary web scripts or HTML by passing a specially crafted payload through the Name parameter. Exploiting this vulnerability could lead to unauthorized actions being performed on behalf of users, compromising the integrity and security of the web application.
