Vulnerability Details CVE-2022-3893
Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permissions to inject arbitrary HTML into the custom menu navigation of the application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.4%
CVSS Severity
CVSS v3 Score 2.3
Products affected by CVE-2022-3893
-
cpe:2.3:a:hallowelt:bluespice:4.1.0
-
cpe:2.3:a:hallowelt:bluespice:4.1.1
-
cpe:2.3:a:hallowelt:bluespice:4.1.2
-
cpe:2.3:a:hallowelt:bluespice:4.1.3
-
cpe:2.3:a:hallowelt:bluespice:4.1.4
-
cpe:2.3:a:hallowelt:bluespice:4.2