Description
A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Value parameter after clicking "Create".
Remediation
References
Related Vulnerabilities
Joomla Improper Input Validation Vulnerability (CVE-2021-26036)
WordPress Plugin Mailing List 'wpabspath' Parameter Remote File Include (1.3.3)
WordPress Plugin Nelio AB Testing Server-Side Request Forgery (4.5.10)
Django Improper Input Validation Vulnerability (CVE-2011-4139)
WordPress Plugin Testimonial-Best Testimonial Slider Cross-Site Scripting (2.1.6)