Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to /rukovoditel_2.4.1/index.php?module=configuration/save&redirect_to=configuration/application.
References
Link Resource
https://github.com/joelister/Persistent-XSS-on-qdPM-9.1/issues/3 Exploit Issue Tracking Third Party Advisory
https://github.com/joelister/Persistent-XSS-on-qdPM-9.1/issues/5 Exploit Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-08-26T17:28:45

Updated: 2021-08-26T17:28:44

Reserved: 2020-08-13T00:00:00


Link: CVE-2020-18469

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-08-26T18:15:07.710

Modified: 2021-08-27T21:03:15.467


Link: CVE-2020-18469

JSON object: View

cve-icon Redhat Information

No data.

CWE