CVE-2023-28025 – An HTML injection vulnerability can affect HCL BigFix Mobile / Modern Client Management
https://notcve.org/view.php?id=CVE-2023-28025
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage. Debido a esta vulnerabilidad, el operador maestro podría potencialmente incorporar una etiqueta SVG en HTML, lo que generaría una ventana emergente de alerta que muestra una cookie. Para mitigar las vulnerabilidades XSS almacenadas, una medida preventiva implica sanitizar y validar minuciosamente todas las entradas del usuario antes de procesarlas y almacenarlas en el almacenamiento del servidor. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109318 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-27781 – HCL BigFix Mobile / Modern Client Management is vulnerable to stored cross-site scripting
https://notcve.org/view.php?id=CVE-2021-27781
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie. El operador de Master puede ser capaz de insertar la etiqueta de script en HTML con la cookie de visualización de alertas • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098028 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-27780 – HCL BigFix Mobile / Modern Client Management is vulnerable to unauthenticated XML interaction
https://notcve.org/view.php?id=CVE-2021-27780
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment. El software puede ser vulnerable tanto a la interacción XML no autenticada como a la inscripción de dispositivos no autenticados • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098028 • CWE-112: Missing XML Validation •
CVE-2021-27783 – HCL BigFix Mobile / Modern Client Management is vulnerable to sensitive information exposure
https://notcve.org/view.php?id=CVE-2021-27783
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed. El archivo PPKG generado por el usuario para Bulk Enroll puede tener expuesta información confidencial sin cifrar • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098586 • CWE-311: Missing Encryption of Sensitive Data •