Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to /rukovoditel_2.4.1/index.php?module=configuration/save&redirect_to=configuration/application.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/joelister/Persistent-XSS-on-qdPM-9.1/issues/3 | Exploit Issue Tracking Third Party Advisory | 
| https://github.com/joelister/Persistent-XSS-on-qdPM-9.1/issues/5 | Exploit Issue Tracking Third Party Advisory | 
Configurations
                    Information
                Published : 2021-08-26 11:15
Updated : 2021-08-27 14:03
NVD link : CVE-2020-18469
Mitre link : CVE-2020-18469
JSON object : View
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
                rukovoditel
- rukovoditel
 


