Rukovoditel

Rukovoditel

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.92%
  • Veröffentlicht 09.07.2021 22:15:08
  • Zuletzt bearbeitet 21.11.2024 05:28:38

A stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.

Exploit
  • EPSS 3.66%
  • Veröffentlicht 09.07.2021 22:15:08
  • Zuletzt bearbeitet 21.11.2024 05:28:38

A stored cross site scripting (XSS) vulnerability in the 'Users Access Groups' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.

Exploit
  • EPSS 5.13%
  • Veröffentlicht 09.07.2021 22:15:08
  • Zuletzt bearbeitet 21.11.2024 05:28:38

A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.

Exploit
  • EPSS 1.65%
  • Veröffentlicht 09.07.2021 22:15:08
  • Zuletzt bearbeitet 21.11.2024 05:28:38

A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' parameter.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 29.04.2021 15:15:11
  • Zuletzt bearbeitet 21.11.2024 06:03:32

Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials.

Exploit
  • EPSS 3.17%
  • Veröffentlicht 09.04.2021 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:01:34

An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigge...

Exploit
  • EPSS 3.37%
  • Veröffentlicht 09.04.2021 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:01:34

An exploitable SQL injection vulnerability exists in the "access_rules/rules_form" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to...

Exploit
  • EPSS 3.26%
  • Veröffentlicht 09.04.2021 18:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:33

An exploitable SQL injection vulnerability exists in the "forms_fields_rules/rules" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request t...

  • EPSS 0.45%
  • Veröffentlicht 14.09.2020 12:15:10
  • Zuletzt bearbeitet 21.11.2024 05:12:50

Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code to the filename.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 27.04.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:42

In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus, an attacker can inject malicious script to steal all users' valuable data.