VYPR
Unrated severityNVD Advisory· Published Dec 16, 2025· Updated Apr 7, 2026

Rukovoditel 3.4.1 Multiple Stored Cross-Site Scripting via Comments

CVE-2023-53897

Description

Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.