An HTML injection vulnerability can affect HCL BigFix Mobile / Modern Client Management
CVE-2023-28025
6.6MEDIUM
What is CVE-2023-28025?
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.
Affected Version(s)
HCL BigFix Mobile / Modern Client Management <= 3.1