Description
A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Circles Gallery Cross-Site Scripting (1.0.10)
WordPress Plugin Facebook Page Photo Gallery Cross-Site Scripting (2.0.9)
WordPress Plugin bbPress Cross-Site Scripting (2.5.8)
WordPress Plugin Swift Landing Page Cross-Site Request Forgery (1.1)
WordPress Plugin SMTP Mailer Cross-Site Request Forgery (1.0.6)