CVE-2020-11821: Rukovoditel
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them.
Affected products
- Rukovoditel Rukovoditel: version 2.5.2 only
Published 2020-04-27. Last modified 2026-06-17.