Stored Cross-Site Scripting Vulnerability in Rukovoditel by Rukovoditel
CVE-2022-44952
5.4MEDIUM
What is CVE-2022-44952?
Rukovoditel v3.2.1 contains a stored cross-site scripting vulnerability located in the /index.php?module=configuration/application endpoint. This flaw allows unauthorized users to inject arbitrary web scripts or HTML through the Copyright Text field by submitting a specially crafted payload after selecting 'Add'. Successful exploitation of this vulnerability can lead to the execution of malicious scripts in users' browsers, potentially compromising their data and security.
