mirror of
https://github.com/0xMarcio/cve.git
synced 2026-02-12 22:53:11 +00:00
684 B
684 B
CVE-2019-7541
Description
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
POC
Reference
- http://packetstormsecurity.com/files/151657/Rukovoditel-Project-Management-CRM-2.4.1-Cross-Site-Scripting.html
- https://www.exploit-db.com/exploits/46366/