Medium severity5.4NVD Advisory· Published Dec 16, 2025· Updated Jun 17, 2026
CVE-2023-53897
CVE-2023-53897
Description
Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=3.4.1+ 2 more
- (no CPE)range: <=3.4.1
- cpe:2.3:a:rukovoditel:rukovoditel:3.4.1:*:*:*:*:*:*:*
- (no CPE)range: 3.4.1
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/51548nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/rukovoditel-multiple-stored-cross-site-scripting-via-commentsnvdExploitThird Party Advisory
- www.rukovoditel.netnvdProduct
News mentions
0No linked articles in our index yet.