CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 2.1. See the original NVD description below for full technical details.
CVE
CVE-2023-42431
Severity
LOW
CVSS
2.1
EPSS
0.34%
Original NVD Description
Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context.
Related CVEs
Other vulnerabilities affecting the same vendor(s)