Known Vulnerabilities for Bluespice by Hallowelt
Listed below are 10 of the newest known vulnerabilities associated with "Bluespice" by "Hallowelt".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-42431 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary... | 5.4 - MEDIUM | 2023-10-30 | 2023-11-08 |
| CVE-2022-42001 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceBookshelf extension of BlueSpice allows user with regular account and ed... | 5.4 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-42000 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceSocialProfile extension of BlueSpice allows user with comment permission... | 5.4 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-41814 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceFoundation extension of BlueSpice allows user with regular account and e... | 5.4 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-41789 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows logged in user with edit permissions ... | 5.4 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-41611 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows user with admin privileges to inject ... | 4.8 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-3958 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account and ... | 5.4 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-3895 json | Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output arbi... | 6.1 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-3893 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permissions to ... | 4.8 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-2511 json | Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to inject arb... | 6.1 - MEDIUM | 2022-07-22 | 2022-07-27 |