CVE-2024-34469: Rukovoditel
High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.
Affected products
- Rukovoditel Rukovoditel: before 3.5.3 (fixed in 3.5.3)
Published 2024-05-04. Last modified 2026-06-17.