Show filters
318 Total Results
Displaying 111-120 of 318
Sort by:
Attacker Value
Unknown
CVE-2023-37498
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It is possible that an attacker could potentially escalate their privileges.
0
Attacker Value
Unknown
CVE-2023-37497
Disclosure Date: August 03, 2023 (last updated February 25, 2025)
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service.
0
Attacker Value
Unknown
CVE-2023-37496
Disclosure Date: August 01, 2023 (last updated February 25, 2025)
HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
0
Attacker Value
Unknown
CVE-2023-28014
Disclosure Date: July 27, 2023 (last updated February 25, 2025)
HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.
0
Attacker Value
Unknown
CVE-2023-28012
Disclosure Date: July 27, 2023 (last updated February 25, 2025)
HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.
0
Attacker Value
Unknown
CVE-2023-28013
Disclosure Date: July 26, 2023 (last updated February 25, 2025)
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
0
Attacker Value
Unknown
CVE-2023-28023
Disclosure Date: July 18, 2023 (last updated February 25, 2025)
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network).
0
Attacker Value
Unknown
CVE-2023-28021
Disclosure Date: July 18, 2023 (last updated February 25, 2025)
The BigFix WebUI uses weak cipher suites.
0
Attacker Value
Unknown
CVE-2023-28020
Disclosure Date: July 18, 2023 (last updated February 25, 2025)
URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
0
Attacker Value
Unknown
CVE-2023-28019
Disclosure Date: July 18, 2023 (last updated February 25, 2025)
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.
0