Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.