CVE-2023-28025

MEDIUM

HCL BigFix Modern Client Management < 3.2 - Stored Cross-Site Scripting via SVG Tag Injection

Title source: llm
STIX 2.1

Description

Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.

References (1)

Core 1

Scores

CVSS v3 6.6
EPSS 0.0006
EPSS Percentile 17.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Details

CWE
CWE-79
Status published
Products (1)
hcltech/bigfix_modern_client_management < 3.2
Published Dec 21, 2023
Tracked Since Feb 18, 2026