Back to Database
Status published
Low
CVE-2022-3893
Potential XSS on custom menu navigation
Vulnerability Description
Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permissions to inject arbitrary HTML into the custom menu navigation of the application.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3893
Credits & Attribution
No credits recorded in the NVD database.
More from Hallo Welt! GmbH
View All →CVE-2025-58114
Potential XSS in Extension:CognitiveProcessDesigner
Medium
5.9
CVE-2025-57880
Potential XSS in Extension:BlueSpiceWhoIsOnline
Medium
5.9
CVE-2025-48007
Potential XSS in Extension:BlueSpiceAvatars
Medium
5.9
CVE-2025-46703
Potential XSS in Extension:AtMentions
Medium
5.9
CVE-2023-42431
Potential XSS on user preferences page
Low
2.1
Affected Vendor
Hallo Welt! GmbH
View all reports →Affected Software
BlueSpice
Vulnerable Versions:
4
Timeline
Official Publish:
November 15th, 2022
Last Modified:
April 29th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N