{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-10T22:13:39.982","vulnerabilities":[{"cve":{"id":"CVE-2023-42431","sourceIdentifier":"security@bluespice.com","published":"2023-10-30T11:15:39.267","lastModified":"2024-11-21T08:22:31.247","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context."},{"lang":"es","value":"Vulnerabilidad de Cross-Site Scripting (XSS) en la extensión BlueSpiceAvatars de BlueSpice permite al usuario que ha iniciado sesión inyectar HTML arbitrario en el cuadro de diálogo de la imagen de perfil en Especial:Preferencias. Esto sólo se aplica al contexto del usuario genuino."}],"metrics":{"cvssMetricV31":[{"source":"security@bluespice.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N","baseScore":2.1,"baseSeverity":"LOW","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}]},"weaknesses":[{"source":"security@bluespice.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hallowelt:bluespice:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndExcluding":"3.2.10.1","matchCriteriaId":"BF1F2433-46DE-4702-8E7F-86EDC716AA5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:hallowelt:bluespice:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"4.3.3","matchCriteriaId":"FFF74443-3D2C-489C-803F-3FA8F09FBE0A"}]}]}],"references":[{"url":"https://en.wiki.bluespice.com/wiki/Security:Security_Advisories/BSSA-2023-02","source":"security@bluespice.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://en.wiki.bluespice.com/wiki/Security:Security_Advisories/BSSA-2023-02","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}