CVE-2023-53898
MEDIUMRukovoditel 3.4.1 - XSS
Title source: llmDescription
Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers.
Exploits (1)
exploitdb
WORKING POC
by Mirabbas Ağalarov · textwebappsphp
https://www.exploit-db.com/exploits/51548
Scores
CVSS v3
5.4
EPSS
0.0005
EPSS Percentile
14.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
rukovoditel/rukovoditel
3.4.1
Rukovoditel/Rukovoditel
3.4.1
Published
Dec 16, 2025
Tracked Since
Feb 18, 2026