HCL BigFix Platform is affected by Unathenticated Stored Cross-Site Scripting (XSS)
CVE-2023-37520
What is CVE-2023-37520?
An unauthenticated stored cross-site scripting (XSS) vulnerability has been identified in BigFix Server version 9.5.12.68. This vulnerability resides in the Gather Status Report feature, which is served by the BigFix Relay. Attackers could exploit this XSS vulnerability to execute arbitrary scripts in the context of an affected user’s browser, leading to potential data exfiltration and unauthorized access to sensitive information. Proper remediation measures are essential to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HCL BigFix Platform 9.5.x, 10.0.x, 11.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved