Stored Cross-Site Scripting Issue in Rukovoditel by Rukovoditel
CVE-2022-44950
5.4MEDIUM
What is CVE-2022-44950?
A vulnerability has been identified in Rukovoditel v3.2.1 that allows for stored cross-site scripting attacks through the Add New Field function. This security flaw permits attackers to inject malicious scripts or HTML content by exploiting the Name field, potentially compromising the integrity of the web application. When this payload is executed, it can lead to unauthorized actions or data exposure, making it imperative for users to apply security updates and practices to mitigate risks.
