CVE-2022-2511
22.07.2022, 16:15
Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to inject arbitrary HTML into a page using the title parameter of the call URL.
Vendor | Product | Version |
---|---|---|
hallowelt | bluespice | 𝑥 < 4.1.3 |
𝑥
= Vulnerable software versions