Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.
References
| Link | Resource |
|---|---|
| https://forum.rukovoditel.net/viewtopic.php?t=5071 | Exploit Issue Tracking Vendor Advisory |
| https://forum.rukovoditel.net/viewtopic.php?t=5071 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-05-04 20:15
Updated : 2025-06-17 15:01
NVD link : CVE-2024-34468
Mitre link : CVE-2024-34468
CVE.ORG link : CVE-2024-34468
JSON object : View
Products Affected
rukovoditel
- rukovoditel
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
