Rukovoditel
by Rukovoditel
Source repositories
CVEs (53)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11818 | Hig | 0.57 | 8.8 | 0.01 | Apr 16, 2020 | In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed with another user's valid token. Thus, an attacker can change the Admin password by using a CSRF attack and escalate his/her privileges. | ||
| CVE-2020-13590 | Hig | 0.47 | 7.2 | 0.01 | Apr 18, 2022 | Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities,… | ||
| CVE-2024-34469 | Hig | 0.46 | 7.1 | 0.01 | May 4, 2024 | Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save. | ||
| CVE-2019-7541 | Med | 0.43 | 6.1 | 0.03 | May 7, 2019 | Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring. | ||
| CVE-2019-7400 | Med | 0.43 | 6.1 | 0.06 | Feb 5, 2019 | Rukovoditel before 2.4.1 allows XSS. | ||
| CVE-2024-34468 | Med | 0.40 | 6.1 | 0.00 | May 4, 2024 | Rukovoditel before 3.5.3 allows XSS via user_photo to My Page. | ||
| CVE-2020-21732 | Med | 0.40 | 6.1 | 0.01 | Sep 14, 2020 | Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code to the filename. | ||
| CVE-2020-11822 | Med | 0.40 | 6.1 | 0.01 | Apr 27, 2020 | In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus, an attacker can inject malicious script to steal all users' valuable data. | ||
| CVE-2023-53898 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers. | ||
| CVE-2023-53897 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers. | ||
| CVE-2022-44952 | Med | 0.35 | 5.4 | 0.01 | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text… | ||
| CVE-2022-44951 | Med | 0.35 | 5.4 | 0.01 | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload… | ||
| CVE-2022-44950 | Med | 0.35 | 5.4 | 0.01 | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload… | ||
| CVE-2022-44949 | Med | 0.35 | 5.4 | 0.01 | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload… | ||
| CVE-2022-44948 | Med | 0.35 | 5.4 | 0.01 | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected… | ||
| CVE-2022-44947 | Med | 0.35 | 5.4 | 0.01 | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=entities/listing_types&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted… | ||
| CVE-2022-44946 | Med | 0.35 | 5.4 | 0.01 | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload… | ||
| CVE-2022-44944 | Med | 0.35 | 5.4 | 0.01 | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted… | ||
| CVE-2022-43170 | Med | 0.35 | 5.4 | 0.01 | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title… | ||
| CVE-2022-43169 | Med | 0.35 | 5.4 | 0.01 | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter… |
- risk 0.57cvss 8.8epss 0.01
In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed with another user's valid token. Thus, an attacker can change the Admin password by using a CSRF attack and escalate his/her privileges.
- risk 0.47cvss 7.2epss 0.01
Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities,…
- risk 0.46cvss 7.1epss 0.01
Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.
- risk 0.43cvss 6.1epss 0.03
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
- risk 0.43cvss 6.1epss 0.06
Rukovoditel before 2.4.1 allows XSS.
- risk 0.40cvss 6.1epss 0.00
Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.
- risk 0.40cvss 6.1epss 0.01
Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code to the filename.
- risk 0.40cvss 6.1epss 0.01
In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus, an attacker can inject malicious script to steal all users' valuable data.
- risk 0.35cvss 5.4epss 0.00
Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers.
- risk 0.35cvss 5.4epss 0.00
Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.
- risk 0.35cvss 5.4epss 0.01
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text…
- risk 0.35cvss 5.4epss 0.01
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload…
- risk 0.35cvss 5.4epss 0.01
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload…
- risk 0.35cvss 5.4epss 0.01
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload…
- risk 0.35cvss 5.4epss 0.01
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…
- risk 0.35cvss 5.4epss 0.01
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=entities/listing_types&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted…
- risk 0.35cvss 5.4epss 0.01
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload…
- risk 0.35cvss 5.4epss 0.01
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted…
- risk 0.35cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title…
- risk 0.35cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter…
Page 2 of 3