Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permissions to inject arbitrary HTML into the custom menu navigation of the application.
History

Tue, 29 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HW

Published: 2022-11-15T14:24:48.875Z

Updated: 2025-04-29T20:12:41.873Z

Reserved: 2022-11-08T00:00:00.000Z

Link: CVE-2022-3893

cve-icon Vulnrichment

Updated: 2024-08-03T01:20:58.777Z

cve-icon NVD

Status : Modified

Published: 2022-11-15T15:15:10.813

Modified: 2024-11-21T07:20:27.953

Link: CVE-2022-3893

cve-icon Redhat

No data.