Vulnerability Details CVE-2022-41611
Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows user with admin privileges to inject arbitrary HTML into the main navigation of the application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.8%
CVSS Severity
CVSS v3 Score 2.3
Products affected by CVE-2022-41611
-
cpe:2.3:a:hallowelt:bluespice:4.1.0
-
cpe:2.3:a:hallowelt:bluespice:4.1.1
-
cpe:2.3:a:hallowelt:bluespice:4.1.2
-
cpe:2.3:a:hallowelt:bluespice:4.1.3
-
cpe:2.3:a:hallowelt:bluespice:4.1.4
-
cpe:2.3:a:hallowelt:bluespice:4.2