In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus, an attacker can inject malicious script to steal all users' valuable data.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-04-27T14:24:18
Updated: 2024-08-04T11:42:00.587Z
Reserved: 2020-04-16T00:00:00
Link: CVE-2020-11822
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-27T15:15:12.580
Modified: 2024-11-21T04:58:42.317
Link: CVE-2020-11822
Redhat
No data.