CVE-2022-3958: Hallowelt Bluespice

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the personal menu navigation of their own and other users. This allows for targeted attacks.

Affected products

  • Hallowelt Bluespice: from 4.1.0, before 4.2.1 (fixed in 4.2.1)

Published 2022-11-15. Last modified 2026-06-17.