Description
Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-46883 | Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context. |
References
History
No history.
Status: PUBLISHED
Assigner: HW
Published:
Updated: 2024-09-06T18:06:33.247Z
Reserved: 2023-10-16T14:12:02.578Z
Link: CVE-2023-42431
Updated: 2024-08-02T19:16:51.059Z
Status : Modified
Published: 2023-10-30T11:15:39.267
Modified: 2024-11-21T08:22:31.247
Link: CVE-2023-42431
No data.
OpenCVE Enrichment
No data.
EUVD