VYPR
Unrated severityNVD Advisory· Published Nov 15, 2022· Updated Apr 29, 2025

Potential XSS in common user interface component library

CVE-2022-3895

Description

Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output arbitrary HTML (XSS).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

BlueSpice 4.x and Common User Interface 3.0.x are vulnerable to stored XSS due to unsanitized output in UI elements.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the Common User Interface (CUI) component of BlueSpice 4.x (CUI 3.0.x versions prior to 3.0.5). Some UI elements fail to properly sanitize output, allowing arbitrary HTML injection [1]. The vulnerability affects BlueSpice 4.x with CUI 3.0.x up to, but not including, 3.0.5 [1].

Exploitation

An attacker needs to be able to inject malicious script or HTML into UI elements processed by the Common User Interface component. The exact attack vector is not detailed in the available references, but the issue lies in the lack of output sanitization, suggesting that user-controllable data is rendered without proper escaping [1]. This could be exploited via any input field or data source that feeds into the vulnerable UI elements.

Impact

Successful exploitation allows an attacker to execute arbitrary HTML and JavaScript in the context of the victim's browser session. This could lead to data theft, session hijacking, or defacement, depending on the attacker's goals and the victim's privileges within the BlueSpice application [1].

Mitigation

The issue is fixed in Common User Interface 3.0.5, which is included in BlueSpice 4.2.1 or later [1]. Users should upgrade to BlueSpice 4.2.1 or ensure CUI is updated to 3.0.5 or later. The vulnerability was discovered during an internal security audit [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.