VYPR

Rukovoditel

by Rukovoditel

CVEs (3)

  • CVE-2023-53913Dec 17, 2025
    risk 0.00cvss epss 0.00

    Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

  • CVE-2023-53898Dec 16, 2025
    risk 0.00cvss epss 0.00

    Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers.

  • CVE-2023-53897Dec 16, 2025
    risk 0.00cvss epss 0.00

    Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.