Reflected Cross-Site Scripting Vulnerability in HCL BigFix Platform Could Lead to Malicious Code Execution
CVE-2023-37527
5.4MEDIUM
Summary
A reflected cross-site scripting (XSS) vulnerability exists in the Web Reports component of HCL BigFix Platform. This flaw can enable an attacker to inject malicious JavaScript code via remote means, which could execute within the user’s application session or in the database during content rendering on a web page. If exploited, this vulnerability can lead to unauthorized data access or manipulation, compromising user data and application integrity.
Affected Version(s)
BigFix Platform 9.5 - 9.5.23, 10 - 10.0.10
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved