Rukovoditel Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2022-45020 - Vulnerability Database

Rukovoditel Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2022-45020

High
Reference: CVE-2022-45020
Title: Rukovoditel Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.phpmoduleusers/login. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.