Show filters
318 Total Results
Displaying 111-120 of 318
Sort by:
Attacker Value
Unknown

CVE-2023-37498

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator.  It is possible that an attacker could potentially escalate their privileges.
Attacker Value
Unknown

CVE-2023-37497

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service.
Attacker Value
Unknown

CVE-2023-37496

Disclosure Date: August 01, 2023 (last updated February 25, 2025)
HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
Attacker Value
Unknown

CVE-2023-28014

Disclosure Date: July 27, 2023 (last updated February 25, 2025)
HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.
Attacker Value
Unknown

CVE-2023-28012

Disclosure Date: July 27, 2023 (last updated February 25, 2025)
HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.
Attacker Value
Unknown

CVE-2023-28013

Disclosure Date: July 26, 2023 (last updated February 25, 2025)
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
Attacker Value
Unknown

CVE-2023-28023

Disclosure Date: July 18, 2023 (last updated February 25, 2025)
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 
Attacker Value
Unknown

CVE-2023-28021

Disclosure Date: July 18, 2023 (last updated February 25, 2025)
The BigFix WebUI uses weak cipher suites.
Attacker Value
Unknown

CVE-2023-28020

Disclosure Date: July 18, 2023 (last updated February 25, 2025)
 URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
Attacker Value
Unknown

CVE-2023-28019

Disclosure Date: July 18, 2023 (last updated February 25, 2025)
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.