CVE-2020-11821: Rukovoditel

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them.

Affected products

Published 2020-04-27. Last modified 2026-06-17.