vendor:
Rukovoditel ERP & CRM
by:
Javier Olmedo
6.1
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Rukovoditel ERP & CRM
Affected Version From: 2.4.1
Affected Version To: 2.4.1
Patch Exists: YES
Related CWE: 2019-7400
CPE: a:rukovoditel:rukovoditel_erp_and_crm
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Linux
2019
Rukovoditel ERP & CRM 2.4.1 – ‘path’ Cross-Site Scripting
The 'path' parameter in Rukovoditel ERP & CRM 2.4.1 is vulnerable to Reflected Cross-Site Scripting (XSS) attacks through a GET request in index.php resource. The payload used for this exploit is '"><img src=a onerror=alert("VULNERABLE")>'
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.