Description
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text field after clicking "Add".
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Coder-add custom html, css and js code SQL Injection (2.5.3)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1000398)
WordPress Plugin WP htaccess Control Unspecified Vulnerability (2.4)
Question2Answer Improper Input Validation Vulnerability (CVE-2017-12775)