CVE-2023-37527
MEDIUMHCL BigFix Platform 9.5-9.5.23 - Reflected Cross-Site Scripting in Web Reports
Title source: llmDescription
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.
References (1)
Core 1
Core References
Scores
CVSS v3
5.4
EPSS
0.0012
EPSS Percentile
30.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
hcltech/bigfix_platform
11.0.0
hcltech/bigfix_platform
9.5 - 9.5.24
Published
Feb 02, 2024
Tracked Since
Feb 18, 2026