S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 9, 2024

CVE-2020-35987 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Rukovoditel affects v. 2.7.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-35987
5.4
CVSS

A stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Detecting and Addressing Rukovoditel's CVE-2020-35987 Vulnerability

Streamlining Project Management with Rukovoditel

Rukovoditel stands as a versatile CRM system builder, empowering businesses across diverse industries to tailor project management solutions to their specific operational needs. From enhancing customer service to fostering seamless collaboration, Rukovoditel serves as an indispensable tool for optimizing productivity and efficiency in project management.

CVE-2020-35987 Vulnerability

The CVE-2020-35987 vulnerability, discovered within Rukovoditel version 2.7.2, manifests as a stored Cross-Site Scripting (XSS) flaw within the 'Entities List' feature. This security loophole enables authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter. The exploitation of this vulnerability presents a significant threat to the integrity and security of digital assets.

Consequences of CVE-2020-35987 Vulnerability

When exploited by malicious cyber attackers, the consequences of the CVE-2020-35987 vulnerability can be severe. Unauthorized access and data manipulation, potential service disruption, and compromised information integrity are among the risks that organizations face when this vulnerability is leveraged for nefarious purposes, highlighting the urgent need for proactive mitigation measures.

Empowering Organizations with S4E

For organizations yet to embrace the services of S4E, the platform offers continuous threat exposure management, providing a dedicated scanner to detect the CVE-2020-35987 vulnerability within digital assets. By joining the S4E platform, non-members can fortify their cybersecurity posture, mitigate potential exploits, and safeguard the continuity of essential operations in the face of evolving cyber threats.

 

References

Solution Advice

You must do the following to fix the vulnerability:

  • Update Rukovoditel to the latest version
  • Apply security patches provided by the Rukovoditel developers
  • Regularly conduct vulnerability scanning and penetration testing
  • Implement input validation and output encoding to mitigate XSS vulnerabilities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-35987 scanner - Cross-Site Scripting (XSS) vulnerability in Rukovoditel | S4E