Stored Cross-Site Scripting Vulnerability in Rukovoditel by Rukovoditel
CVE-2022-44944
5.4MEDIUM
What is CVE-2022-44944?
Rukovoditel v3.2.1 contains a vulnerability that enables stored cross-site scripting, specifically in the Add Announcement function. This security flaw allows malicious actors to inject and execute arbitrary web scripts or HTML by exploiting a crafted payload in the Title field. Such an attack can facilitate theft of sensitive user data, unauthorized actions on behalf of users, and other harmful consequences. To protect users and maintain the integrity of web applications, it is imperative for system administrators to apply available updates and security patches.
