Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output arbitrary HTML (XSS).
Metrics
Affected Vendors & Products
Fixes
Solution
Upgrade to Common User Interface 3.0.5 or later. This is included in BlueSpice 4.2.1 or later.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: HW
Published:
Updated: 2025-04-29T18:12:08.089Z
Reserved: 2022-11-08T00:00:00.000Z
Link: CVE-2022-3895

Updated: 2024-08-03T01:20:58.454Z

Status : Modified
Published: 2022-11-15T15:15:12.167
Modified: 2024-11-21T07:20:29.067
Link: CVE-2022-3895

No data.

No data.