HCL BigFix Platform is affected by Unathenticated Stored Cross-Site Scripting (XSS)
CVE-2023-37520
7.7HIGH
What is CVE-2023-37520?
An unauthenticated stored cross-site scripting (XSS) vulnerability has been identified in BigFix Server version 9.5.12.68. This vulnerability resides in the Gather Status Report feature, which is served by the BigFix Relay. Attackers could exploit this XSS vulnerability to execute arbitrary scripts in the context of an affected user’s browser, leading to potential data exfiltration and unauthorized access to sensitive information. Proper remediation measures are essential to mitigate the risks associated with this vulnerability.
Affected Version(s)
HCL BigFix Platform 9.5.x, 10.0.x, 11.0.0