6.1
CVSSv3

CVE-2019-7541

Published: 07/05/2019 Updated: 08/05/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Rukovoditel up to and including 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rukovoditel rukovoditel

Exploits

#################################################################### # Exploit Title : Rukovoditel Project Management CRM 241 - XSS Vulnerability (DOM BASED) # Author [ Discovered By ] : Mehmet EMIROGLU # Date : 29/01/2019 # Vendor Homepage : wwwrukovoditelnet/ # Software Link : sourceforgenet/projects/rukovoditel/ # Affected ...