Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3958

Опубликовано: 15 нояб. 2022
Источник: nvd
CVSS3: 3.3
CVSS3: 5.4
EPSS Низкий

Описание

Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the personal menu navigation of their own and other users. This allows for targeted attacks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hallowelt:bluespice:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.2.1 (исключая)

EPSS

Процентиль: 53%
0.00298
Низкий

3.3 Low

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.4
github
около 3 лет назад

Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the personal menu navigation of their own and other users. This allows for targeted attacks.

EPSS

Процентиль: 53%
0.00298
Низкий

3.3 Low

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79