CVE-2023-53897

Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.
Configurations

No configuration.

History

16 Dec 2025, 18:16

Type Values Removed Values Added
References
  • () https://www.vulncheck.com/advisories/rukovoditel-multiple-stored-cross-site-scripting-via-comments -

16 Dec 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-16 17:16

Updated : 2025-12-18 15:08


NVD link : CVE-2023-53897

Mitre link : CVE-2023-53897

CVE.ORG link : CVE-2023-53897


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')