Vulnerabilities
52 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-53913 | Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file. NVD description · AI analysis pending | 6.2 | <1% | PoC ×2 |
| — | |
| CVE-2023-53898 +1 in the same advisory: …53897 | Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers. NVD description · AI analysis pending | 5.1 | <1% | PoC ×2 |
| — | |
| CVE-2024-34469 +1 in the same advisory: …34468 | Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save. Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save. NVD description · AI analysis pending | 7.1 group max | <1% | PoC |
| — | |
| CVE-2022-48175 | Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request. Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2022-45020 | Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=users/login. Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=users/login. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2022-44945 | Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter. Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2022-43288 | Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the order_by parameter at /rukovoditel/index.php?module=logs/view&type=php. Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the order_by parameter at /rukovoditel/index.php?module=logs/view&type=php. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2022-43168 | Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter. Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2022-43185 | A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts o A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter. NVD description · AI analysis pending | 5.4 | 1% | PoC |
| — | |
| CVE-2020-13590 | Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities, this can be done either with administrator credentials or through cross-site request forgery. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2020-18469 +1 in the same advisory: …18470 | Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allo Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to /rukovoditel_2.4.1/index.php?module=configuration/save&redirect_to=configuration/application. NVD description · AI analysis pending | 5.4 | <1% | PoC ×2 |
| — | |
| CVE-2020-13589 +1 in the same advisory: …13588 | An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The entities_id parameter in the 'entities/fields page (mulitple_edit or copy_selected or export function) is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2020-35985 | A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scr A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter. NVD description · AI analysis pending | 5.4 | 1% | PoC |
| — | |
| CVE-2021-30224 | Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials. Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2020-13592 | An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2. An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery. NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2020-21732 | Rukovoditel Project Management app 2.6 is affected by: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code to the filename. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2020-11817 | In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs with the Maintenance Mode setting. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2020-11819 | In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution. In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution. NVD description · AI analysis pending | 9.8 group max | 27% | PoC |
| — | |
| CVE-2019-7541 | Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring. Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring. NVD description · AI analysis pending | 6.1 | 3% | PoC ×2 |
| — |