Lucene search

K
cvelistHCLCVELIST:CVE-2023-37531
HistoryFeb 02, 2024 - 8:07 p.m.

CVE-2023-37531 A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform

2024-02-0220:07:44
HCL
www.cve.org
6
cve-2023-37531
cross-site scripting
hcl bigfix platform
web reports
attacker
javascript code
form field
privileged access

CVSS3

3.3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

AI Score

5.4

Confidence

High

EPSS

0

Percentile

9.0%

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "BigFix Platform",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "9.5 - 9.5.23, 10 - 10.0.10"
      }
    ]
  }
]

CVSS3

3.3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

AI Score

5.4

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVELIST:CVE-2023-37531