Vulnerabilities
Vulnerable Software
Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.
CVSS Score
6.1
EPSS Score
0.003
Published
2024-05-04
Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.
CVSS Score
7.1
EPSS Score
0.009
Published
2024-05-04
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
CVSS Score
6.1
EPSS Score
0.027
Published
2019-05-07
Rukovoditel before 2.4.1 allows XSS.
CVSS Score
6.1
EPSS Score
0.074
Published
2019-02-05
A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishandles extension checking. It accepts uploads of PHP content if the first few characters match GIF data, and the filename ends in ".php" with mixed case, such as the .pHp extension.
CVSS Score
8.8
EPSS Score
0.035
Published
2019-01-02


Contact Us

Shodan ® - All rights reserved