Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers. | |
| Title | Rukovoditel 3.4.1 Multiple Stored Cross-Site Scripting via Configuration | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-16T17:03:46.653Z
Updated: 2025-12-16T21:41:37.905Z
Reserved: 2025-12-16T00:10:40.314Z
Link: CVE-2023-53898
Updated: 2025-12-16T21:41:04.912Z
Status : Received
Published: 2025-12-16T17:16:02.060
Modified: 2025-12-16T18:16:06.803
Link: CVE-2023-53898
No data.