SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-3895

Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output arbitrary HTML (XSS).

MEDIUM 6.1EPSS 0.28%

Does this matter?

Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.

Description

Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output arbitrary HTML (XSS).

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.28% probability · 20th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
hallowelt/bluespice · hallowelt/common user interface
Source
security@bluespice.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.