PT-2024-3329 · Unknown · Rukovoditel

Anton Kartunov

+1

·

Published

2024-04-08

·

Updated

2024-08-01

·

CVE-2024-34469

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Rukovoditel versions prior to 3.5.3
Description The issue is related to a lack of protection for the web page structure when handling the user photo parameter in the "index.php?module=users/registration&action=save" endpoint. This can allow a remote attacker to conduct a cross-site scripting (XSS) attack.
Recommendations For versions prior to 3.5.3, update to version 3.5.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the "index.php?module=users/registration&action=save" endpoint until a patch is available. Avoid using the user photo parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-03592
CVE-2024-34469

Affected Products

Rukovoditel