CVE-2022-2511
EUVD-2022-3476922.07.2022, 16:15
Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to inject arbitrary HTML into a page using the title parameter of the call URL.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hallowelt | bluespice | 𝑥 < 4.1.3 |
𝑥
= Vulnerable software versions