CVE-2023-37520 – HCL BigFix Platform is affected by Unathenticated Stored Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-37520
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay. Vulnerabilidad de Cross-Site Scripting (XSS) almacenado no autenticada identificada en BigFix Server versión 9.5.12.68, lo que permite una posible filtración de datos. Esta vulnerabilidad XSS se encuentra en el Gather Status Report, que proporciona BigFix Relay. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109376 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-37519 – HCL BigFix Platform is affected by Unathenticated Stored Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-37519
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server. Vulnerabilidad de Cross-Site Scripting (XSS) almacenado no autenticada. Esta vulnerabilidad XSS se encuentra en Download Status Report, que proporciona BigFix Server. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109376 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-28025 – An HTML injection vulnerability can affect HCL BigFix Mobile / Modern Client Management
https://notcve.org/view.php?id=CVE-2023-28025
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage. Debido a esta vulnerabilidad, el operador maestro podría potencialmente incorporar una etiqueta SVG en HTML, lo que generaría una ventana emergente de alerta que muestra una cookie. Para mitigar las vulnerabilidades XSS almacenadas, una medida preventiva implica sanitizar y validar minuciosamente todas las entradas del usuario antes de procesarlas y almacenarlas en el almacenamiento del servidor. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109318 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-28022 – HCL Connections is vulnerable to sensitive information disclosure
https://notcve.org/view.php?id=CVE-2023-28022
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data. HCL Connections es afectado por una vulnerabilidad de divulgación de información que podría permitir a un usuario obtener información confidencial a la que no tiene derecho, causada por un manejo inadecuado de los datos de la solicitud. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108433 •
CVE-2023-28017 – HCL Connections is vulnerable to cross-site scripting
https://notcve.org/view.php?id=CVE-2023-28017
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise a user's account then launch other attacks. HCL Connections es vulnerable a un ataque de Cross-Site-Scripting en el que un atacante puede aprovechar este problema para ejecutar código de script arbitrario en el navegador de un usuario desprevenido después de visitar la URL vulnerable que conduce a la ejecución de código de script malicioso. Esto puede permitir al atacante robar credenciales de autenticación basadas en cookies y capturar la cuenta de un usuario y luego lanzar otros ataques. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108264 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •