Lucene search

K
cveHCLCVE-2023-37531
HistoryFeb 29, 2024 - 1:40 a.m.

CVE-2023-37531

2024-02-2901:40:04
HCL
web.nvd.nist.gov
13
cve-2023-37531
cross-site scripting
xss
hcl bigfix platform
web reports
nvd

CVSS3

3.3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

AI Score

4

Confidence

High

EPSS

0

Percentile

9.0%

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "BigFix Platform",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "9.5 - 9.5.23, 10 - 10.0.10"
      }
    ]
  }
]

CVSS3

3.3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

AI Score

4

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2023-37531