Overview
- Description
- Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the personal menu navigation of their own and other users. This allows for targeted attacks.
- Source
- security@bluespice.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:hallowelt:bluespice:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "696F93D5-AB35-4EA3-AEDB-9C868E94ED6D", "versionEndExcluding": "4.2.1", "versionStartIncluding": "4.1.0" } ], "operator": "OR" } ] } ]