Description
A stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Fancy Slideshows Security Bypass (2.4)
Moodle CVE-2021-40695 Vulnerability (CVE-2021-40695)
WordPress Plugin Redirection Local File Inclusion (2.7.3)
WordPress Plugin WP-Stats-Dashboard SQL Injection (2.9.4)
WordPress Plugin GeoDirectory Location Manager Multiple SQL Injection Vulnerabilities (2.1.0.9)