CVE-2020-35987
- EPSS 2.92%
- Veröffentlicht 09.07.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:28:38
A stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
CVE-2020-35986
- EPSS 3.66%
- Veröffentlicht 09.07.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:28:38
A stored cross site scripting (XSS) vulnerability in the 'Users Access Groups' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
CVE-2020-35985
- EPSS 5.13%
- Veröffentlicht 09.07.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:28:38
A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
CVE-2020-35984
- EPSS 1.65%
- Veröffentlicht 09.07.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:28:38
A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' parameter.
CVE-2021-30224
- EPSS 0.11%
- Veröffentlicht 29.04.2021 15:15:11
- Zuletzt bearbeitet 21.11.2024 06:03:32
Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials.
CVE-2020-13592
- EPSS 3.17%
- Veröffentlicht 09.04.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:01:34
An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigge...
CVE-2020-13591
- EPSS 3.37%
- Veröffentlicht 09.04.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:01:34
An exploitable SQL injection vulnerability exists in the "access_rules/rules_form" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to...
CVE-2020-13587
- EPSS 3.26%
- Veröffentlicht 09.04.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:33
An exploitable SQL injection vulnerability exists in the "forms_fields_rules/rules" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request t...
CVE-2020-21732
- EPSS 0.45%
- Veröffentlicht 14.09.2020 12:15:10
- Zuletzt bearbeitet 21.11.2024 05:12:50
Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code to the filename.
CVE-2020-11822
- EPSS 0.29%
- Veröffentlicht 27.04.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:42
In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus, an attacker can inject malicious script to steal all users' valuable data.