ZeroHour

Vulnerabilities

52 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-53913
Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field.

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

NVD description · AI analysis pending
6.2<1% PoC ×2
  • rukovoditel rukovoditel
CVE-2023-53898
+1 in the same advisory: …53897
Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts.

Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers.

NVD description · AI analysis pending
5.1<1% PoC ×2
  • rukovoditel rukovoditel
CVE-2024-34469
+1 in the same advisory: …34468
Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.

Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.

NVD description · AI analysis pending
7.1
group max
<1% PoC
  • rukovoditel rukovoditel
CVE-2022-48175
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.

Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.

NVD description · AI analysis pending
9.82% PoC
  • rukovoditel rukovoditel
CVE-2022-45020
Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=users/login.

Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=users/login. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

NVD description · AI analysis pending
8.8<1% PoC
  • rukovoditel rukovoditel
CVE-2022-44945
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.

Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • rukovoditel rukovoditel
CVE-2022-43288
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the order_by parameter at /rukovoditel/index.php?module=logs/view&type=php.

Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the order_by parameter at /rukovoditel/index.php?module=logs/view&type=php.

NVD description · AI analysis pending
8.8<1% PoC
  • rukovoditel rukovoditel
CVE-2022-43168
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.

Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • rukovoditel rukovoditel
CVE-2022-43185
A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts o

A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

NVD description · AI analysis pending
5.41% PoC
  • rukovoditel rukovoditel
CVE-2020-13590
Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2.

Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities, this can be done either with administrator credentials or through cross-site request forgery.

NVD description · AI analysis pending
7.2<1% PoC
  • rukovoditel rukovoditel
CVE-2020-18469
+1 in the same advisory: …18470
Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allo

Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to /rukovoditel_2.4.1/index.php?module=configuration/save&redirect_to=configuration/application.

NVD description · AI analysis pending
5.4<1% PoC ×2
  • rukovoditel rukovoditel
CVE-2020-13589
+1 in the same advisory: …13588
An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2.

An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The entities_id parameter in the 'entities/fields page (mulitple_edit or copy_selected or export function) is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.

NVD description · AI analysis pending
8.8<1% PoC
  • rukovoditel rukovoditel
CVE-2020-35985
+3 in the same advisory: …35986 …35987 …35984
A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scr

A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.

NVD description · AI analysis pending
5.41% PoC
  • rukovoditel rukovoditel
CVE-2021-30224
Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials.

Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials.

NVD description · AI analysis pending
8.8<1% PoC
  • rukovoditel rukovoditel
CVE-2020-13592
+2 in the same advisory: …13591 …13587
An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2.

An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.

NVD description · AI analysis pending
8.82% PoC
  • rukovoditel rukovoditel
CVE-2020-21732
Rukovoditel Project Management app 2.6 is affected by:

Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code to the filename.

NVD description · AI analysis pending
6.1<1%
  • rukovoditel rukovoditel
CVE-2020-11817
+2 in the same advisory: …11822 …11821
In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value.

In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs with the Maintenance Mode setting.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • rukovoditel rukovoditel
CVE-2020-11819
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution.

In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution.

NVD description · AI analysis pending
9.8
group max
27% PoC
  • rukovoditel rukovoditel
CVE-2019-7541
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.

Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.

NVD description · AI analysis pending
6.13% PoC ×2
  • rukovoditel rukovoditel