Stored Cross-Site Scripting Issue in Rukovoditel by Rukovoditel
CVE-2022-44950

5.4MEDIUM

Key Information:

Vendor
CVE Published:
2 December 2022

What is CVE-2022-44950?

A vulnerability has been identified in Rukovoditel v3.2.1 that allows for stored cross-site scripting attacks through the Add New Field function. This security flaw permits attackers to inject malicious scripts or HTML content by exploiting the Name field, potentially compromising the integrity of the web application. When this payload is executed, it can lead to unauthorized actions or data exposure, making it imperative for users to apply security updates and practices to mitigate risks.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.