📦 Rukovoditel

by Rukovoditel

🔍 What is Rukovoditel?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-53913

HIGH CVSS 8.8 Dec 17, 2025

CVE-2023-53913 is a CSV injection vulnerability in Rukovoditel 3.3.1 that allows authenticated users to inject malicious formulas into user profile fields. When administrators export customer data as ...

CVE-2024-34469

HIGH CVSS 7.1 May 4, 2024

This cross-site scripting (XSS) vulnerability in Rukovoditel allows attackers to inject malicious scripts via the user_photo parameter during user registration. When exploited, it enables session hija...

CVE-2020-13589

HIGH CVSS 8.8 Aug 17, 2021

This SQL injection vulnerability in Rukovoditel Project Management App allows authenticated attackers to execute arbitrary SQL commands through the entities/fields page. Organizations using version 2....

CVE-2021-30224

HIGH CVSS 8.8 Apr 29, 2021

This CSRF vulnerability in Rukovoditel v2.8.3 allows attackers to trick authenticated administrators into unknowingly creating new admin accounts with attacker-controlled credentials. Any organization...

CVE-2020-13591

HIGH CVSS 8.8 Apr 9, 2021

This SQL injection vulnerability in Rukovoditel Project Management App allows authenticated attackers to execute arbitrary SQL commands through the access_rules/rules_form page. Attackers with adminis...

CVE-2024-34468

MEDIUM CVSS 6.1 May 4, 2024

This vulnerability allows cross-site scripting (XSS) attacks via the user_photo parameter on the My Page feature in Rukovoditel. Attackers can inject malicious scripts that execute in victims' browser...