Stored Cross-Site Scripting Vulnerability in Rukovoditel by Rukovoditel
CVE-2022-44949
5.4MEDIUM
What is CVE-2022-44949?
Rukovoditel v3.2.1 is vulnerable to a stored cross-site scripting (XSS) issue, specifically within the Add New Field function located at /index.php?module=entities/fields&entities_id=24. This flaw permits an attacker to inject malicious JavaScript code through a crafted payload in the Short Name field, posing significant risks by potentially allowing unauthorized access to user data and executing unwanted scripts in the context of the user’s browser.
