🔐 CVE Alert

CVE-2023-53897

MEDIUM 5.4

Rukovoditel 3.4.1 Multiple Stored Cross-Site Scripting via Comments

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.

CWE CWE-79
Vendor rukovoditel
Product rukovoditel
Published Dec 16, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for rukovoditel rukovoditel

Be the first to know when new medium vulnerabilities affecting rukovoditel rukovoditel are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Rukovoditel / Rukovoditel
3.4.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
exploit-db.com: https://www.exploit-db.com/exploits/51548 rukovoditel.net: https://www.rukovoditel.net/ vulncheck.com: https://www.vulncheck.com/advisories/rukovoditel-multiple-stored-cross-site-scripting-via-comments

Credits

Mirabbas Ağalarov