Description
A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add".
Remediation
References
Related Vulnerabilities
Apache Tomcat version older than 7.0.30
phpMyAdmin Other Vulnerability (CVE-2007-0203)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1734)
MySQL CVE-2015-0511 Vulnerability (CVE-2015-0511)
Python Inadequate Encryption Strength Vulnerability (CVE-2014-0224)