Description
A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' parameter.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-0503 Vulnerability (CVE-2015-0503)
Oracle Application Server Other Vulnerability (CVE-2007-0286)
Jboss EAP Incomplete List of Disallowed Inputs Vulnerability (CVE-2018-7489)
WordPress Plugin Push Notifications for WordPress (Lite) Cross-Site Request Forgery (6.0)
Zope Web Application Server Other Vulnerability (CVE-2006-3458)