CVE-2023-53897
MEDIUMRukovoditel 3.4.1 - Authenticated Stored Cross-Site Scripting via Project Task Comments
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53897. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary This exploit demonstrates multiple stored XSS vulnerabilities in Rukovoditel 3.4.1. It includes detailed steps and HTTP requests to inject malicious scripts via task comments and application configuration fields.
Description
Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.
Exploits (1)
This exploit demonstrates multiple stored XSS vulnerabilities in Rukovoditel 3.4.1. It includes detailed steps and HTTP requests to inject malicious scripts via task comments and application configuration fields.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N