General-Purpose System Vulnerabilities
Vulnerabilities related to traditional IT systems, servers, and desktop applications.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2020-11818 | In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed … | High (8.8) | 2020-04-16 | General Purpose |
| CVE-2020-11816 | Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the reports_id (POST) pa… | Critical (9.8) | 2020-04-16 | General Purpose |
| CVE-2020-11815 | In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a r… | Critical (9.8) | 2020-04-16 | General Purpose |
| CVE-2020-11814 | A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users… | Medium (5.4) | 2020-04-16 | General Purpose |
| CVE-2020-11813 | In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the configuration page via the copyright text input. Thus,… | Medium (5.4) | 2020-04-16 | General Purpose |