Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2023-37531

Disclosure Date: February 29, 2024 (last updated December 18, 2024)
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.
Attacker Value
Unknown

CVE-2023-37530

Disclosure Date: February 29, 2024 (last updated December 18, 2024)
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information.
Attacker Value
Unknown

CVE-2023-37529

Disclosure Date: February 29, 2024 (last updated December 18, 2024)
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerability as identified in CVE-2023-37530.
Attacker Value
Unknown

CVE-2023-37528

Disclosure Date: February 03, 2024 (last updated February 13, 2024)
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.
Attacker Value
Unknown

CVE-2024-23553

Disclosure Date: February 02, 2024 (last updated February 10, 2024)
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
Attacker Value
Unknown

CVE-2023-37527

Disclosure Date: February 02, 2024 (last updated February 10, 2024)
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.
Attacker Value
Unknown

CVE-2023-37520

Disclosure Date: December 21, 2023 (last updated December 30, 2023)
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.
Attacker Value
Unknown

CVE-2023-37519

Disclosure Date: December 21, 2023 (last updated December 30, 2023)
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server.