🔐 CVE Alert

CVE-2023-53913

HIGH 8.8

Rukovoditel 3.3.1 CSV Injection via User Account Export

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

CWE CWE-1236
Vendor rukovoditel
Product rukovoditel
Published Dec 17, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for rukovoditel rukovoditel

Be the first to know when new high vulnerabilities affecting rukovoditel rukovoditel are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Rukovoditel / Rukovoditel
3.3.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
exploit-db.com: https://www.exploit-db.com/exploits/51490 rukovoditel.net: https://www.rukovoditel.net/ vulncheck.com: https://www.vulncheck.com/advisories/rukovoditel-csv-injection-via-user-account-export

Credits

Mirabbas Ağalarov