Rukovoditel Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-11822
In Rukovoditel 2.5.2 there is a stored XSS vulnerability on the application structure --gt user access groups page. Thus an attacker can inject malicious script to steal all users39 valuable data.