Stored Cross-Site Scripting Flaw in Rukovoditel by Rukovoditel
CVE-2022-44947
5.4MEDIUM
What is CVE-2022-44947?
Rukovoditel version 3.2.1 is vulnerable to a stored cross-site scripting (XSS) flaw located within the Highlight Row feature. This issue occurs when users can insert a malicious script into the Note field after selecting 'Add'. By leveraging this vulnerability, attackers can potentially execute arbitrary web scripts or HTML, compromising web application security and the confidentiality of user data.
