ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-18469”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-18469
Published
2021-08-26
CVSS:
5.4
ShadowTrackr CVSS:
0.4
Summary:
Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to /rukovoditel_2.4.1/index.php?module=configuration/save&redirect_to=configuration/application.