CVE-2023-53897
16.12.2025, 17:16
Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.
| Vendor | Product | Version |
|---|---|---|
| rukovoditel | rukovoditel | 3.4.1 |
𝑥
= Vulnerable software versions