Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Potential XSS on user preferences page
Vulnerability Description
Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
BlueSpice 安全漏洞
Vulnerability Description
BlueSpice是BlueSpice公司的基于MediaWiki引擎的免费Wiki软件。 BlueSpice存在安全漏洞,该漏洞源于BlueSpiceAvatars扩展存在跨站脚本(XSS)漏洞。攻击者可利用该漏洞在profile image对话框中注入任意HTML代码。
CVSS Information
N/A
Vulnerability Type
N/A