Description
Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context.
Published: 2023-10-30
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-46883 Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context.
History

No history.

Subscriptions

Hallowelt Bluespice
cve-icon MITRE

Status: PUBLISHED

Assigner: HW

Published:

Updated: 2024-09-06T18:06:33.247Z

Reserved: 2023-10-16T14:12:02.578Z

Link: CVE-2023-42431

cve-icon Vulnrichment

Updated: 2024-08-02T19:16:51.059Z

cve-icon NVD

Status : Modified

Published: 2023-10-30T11:15:39.267

Modified: 2024-11-21T08:22:31.247

Link: CVE-2023-42431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses