ZeroHour

CVE-2022-42001

CVSS 3.1
5.4 medium
EPSS
<1%p18
Published
()
Modified
Description

Cross-site Scripting (XSS) vulnerability in BlueSpiceBookshelf extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the book navigation.

Vendors
hallowelt
Products
bluespice
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.