Description
In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus, an attacker can inject malicious script to steal all users' valuable data.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ultimate Gift Cards For WooCommerce Cross-Site Request Forgery (2.1.1)
Oracle JRE CVE-2017-10349 Vulnerability (CVE-2017-10349)
MySQL CVE-2019-2993 Vulnerability (CVE-2019-2993)
WordPress Plugin Edwiser Bridge-WordPress Moodle LMS Integration Unspecified Vulnerability (2.0.7)
WordPress 4.2.x Denial of Service Vulnerability (4.2 - 4.2.19)