CVE-2020-18469
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to /rukovoditel_2.4.1/index.php?module=configuration/save&redirect_to=configuration/application.
Una vulnerabilidad de tipo cross-site scripting (XSS) almacenado en el campo Copyright Text que se encuentra en la página Application bajo el menú Configuration en Rukovoditel versión 2.4.1, permite a atacantes remotos inyectar script web o HTML arbitrario por medio de un nombre de sitio web diseñado al hacer una petición HTTP POST autenticada al archivo /rukovoditel_2.4.1/index.php?module=configuration/save&redirect_to=configuration/application.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-13 CVE Reserved
- 2021-08-26 CVE Published
- 2023-03-19 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/joelister/Persistent-XSS-on-qdPM-9.1/issues/3 | 2024-08-04 | |
https://github.com/joelister/Persistent-XSS-on-qdPM-9.1/issues/5 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rukovoditel Search vendor "Rukovoditel" | Rukovoditel Search vendor "Rukovoditel" for product "Rukovoditel" | 2.4.1 Search vendor "Rukovoditel" for product "Rukovoditel" and version "2.4.1" | - |
Affected
|