Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output arbitrary HTML (XSS).
References
Link | Resource |
---|---|
https://en.wiki.bluespice.com/wiki/Security:Security_Advisories/BSSA-2022-08 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2022-11-15 15:15
Updated : 2022-11-16 19:43
NVD link : CVE-2022-3895
Mitre link : CVE-2022-3895
CVE.ORG link : CVE-2022-3895
JSON object : View
Products Affected
hallowelt
- common_user_interface
- bluespice
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')