CVE-2020-11822: Rukovoditel

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus, an attacker can inject malicious script to steal all users' valuable data.

Affected products

Published 2020-04-27. Last modified 2026-06-17.