Rukovoditel Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-11822
Reference:
CVE-2020-11822
Title:
Rukovoditel Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
In Rukovoditel 2.5.2 there is a stored XSS vulnerability on the application structure --gt user access groups page. Thus an attacker can inject malicious script to steal all users39 valuable data.