Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: HW

Published:

Updated: 2024-09-06T18:06:33.247Z

Reserved: 2023-10-16T14:12:02.578Z

Link: CVE-2023-42431

cve-icon Vulnrichment

Updated: 2024-08-02T19:16:51.059Z

cve-icon NVD

Status : Modified

Published: 2023-10-30T11:15:39.267

Modified: 2024-11-21T08:22:31.247

Link: CVE-2023-42431

cve-icon Redhat

No data.