CVE-2023-53898
MEDIUMRukovoditel 3.4.1 - Authenticated Stored Cross-Site Scripting via Application Copyright Text
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53898. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary This exploit demonstrates multiple stored XSS vulnerabilities in Rukovoditel 3.4.1. It includes detailed steps and HTTP requests to inject malicious scripts via task comments and application configuration fields.
Description
Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers.
Exploits (1)
This exploit demonstrates multiple stored XSS vulnerabilities in Rukovoditel 3.4.1. It includes detailed steps and HTTP requests to inject malicious scripts via task comments and application configuration fields.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N