vendor:
Rukovoditel Project Management CRM
by:
Mehmet EMIROGLU
6.1
CVSS
MEDIUM
XSS
79
CWE
Product Name: Rukovoditel Project Management CRM
Affected Version From: 2.4.2001
Affected Version To: 2.4.2001
Patch Exists: NO
Related CWE: CVE-2019-7541
CPE: a:rukovoditel_project_management_crm:rukovoditel:2.4.1
Platforms Tested: Wampp, Windows, Lampp
2019
Rukovoditel Project Management CRM 2.4.1 – XSS Vulnerability (DOM BASED)
The Rukovoditel Project Management CRM 2.4.1 version is vulnerable to a DOM based XSS vulnerability. By manipulating the URL and injecting malicious code, an attacker can execute arbitrary scripts in the victim's browser.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate user input before displaying it on the web application.