Description
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.
Remediation
References
Related Vulnerabilities
WordPress Plugin Slideshow Gallery LITE Unspecified Vulnerability (1.7.4.2)
phpBB Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-5173)
WordPress Plugin Affiliates Manager SQL Injection (2.8.6)
Ruby Improper Authentication Vulnerability (CVE-2007-5162)
Apache HTTP Server Improper Authentication Vulnerability (CVE-2017-3167)