PT-2022-27350 · Unknown · Rukovoditel

Anhdq201

·

Published

2022-12-02

·

Updated

2024-02-14

·

CVE-2022-44950

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rukovoditel version 3.2.1
Description A stored cross-site scripting (XSS) issue was found in the Add New Field function at "/index.php?module=entities/fields&entities id=24". This allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Recommendations For Rukovoditel version 3.2.1, consider disabling the Add New Field function at "/index.php?module=entities/fields&entities id=24" until a patch is available to prevent exploitation. Restrict access to the Name field in the affected function to minimize the risk of arbitrary web script or HTML execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-44950

Affected Products

Rukovoditel