Description
Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to inject arbitrary HTML (XSS) on page "Special:SearchCenter", using the search term in the URL.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to BlueSpice 3.2.9, 4.1.1 or higher
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-34768 | Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to inject arbitrary HTML (XSS) on page "Special:SearchCenter", using the search term in the URL. |
References
History
No history.
Status: PUBLISHED
Assigner: HW
Published:
Updated: 2024-09-16T16:38:23.076Z
Reserved: 2022-07-22T00:00:00.000Z
Link: CVE-2022-2510
No data.
Status : Modified
Published: 2022-07-22T16:15:08.297
Modified: 2024-11-21T07:01:08.623
Link: CVE-2022-2510
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD