Home Embedded Vulns General Vulns
CVE ID Description Severity Published Type
CVE-2020-11818 In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed … High (8.8) 2020-04-16 General Purpose
CVE-2020-11816 Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the reports_id (POST) pa… Critical (9.8) 2020-04-16 General Purpose
CVE-2020-11815 In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a r… Critical (9.8) 2020-04-16 General Purpose
CVE-2020-11814 A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users… Medium (5.4) 2020-04-16 General Purpose
CVE-2020-11813 In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the configuration page via the copyright text input. Thus,… Medium (5.4) 2020-04-16 General Purpose