First published: Fri Jul 09 2021(Updated: )
A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rukovoditel Rukovoditel | =2.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-35984 is medium.
The stored XSS vulnerability in Rukovoditel 2.7.2 occurs when authenticated attackers input a crafted payload into the 'Title' parameter of the 'User Alerts' feature.
An attacker exploiting CVE-2020-35984 can execute arbitrary web scripts or HTML on the affected system.
At the moment, there are no known fixes for CVE-2020-35984. It is recommended to update to a newer version if available or use a different software.
More information about CVE-2020-35984 can be found at the following reference: https://github.com/r0ck3t1973/rukovoditel/issues/4