PT-2022-26781 · Unknown · Rukovoditel

Anhdq201

·

Published

2022-10-28

·

Updated

2022-10-28

·

CVE-2022-43164

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rukovoditel version 3.2.1
Description A stored cross-site scripting (XSS) issue in the Global Lists feature, specifically at the "/index.php?module=global lists/lists" endpoint, allows authenticated attackers to execute arbitrary web scripts or HTML. This is achieved by injecting a crafted payload into the Name parameter after clicking "Add".
Recommendations For Rukovoditel version 3.2.1, consider disabling the Global Lists feature until a patch is available. As a temporary workaround, restrict access to the "/index.php?module=global lists/lists" endpoint to minimize the risk of exploitation. Avoid using the Name parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-43164

Affected Products

Rukovoditel