CVE-2023-28025 – An HTML injection vulnerability can affect HCL BigFix Mobile / Modern Client Management
https://notcve.org/view.php?id=CVE-2023-28025
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage. Debido a esta vulnerabilidad, el operador maestro podría potencialmente incorporar una etiqueta SVG en HTML, lo que generaría una ventana emergente de alerta que muestra una cookie. Para mitigar las vulnerabilidades XSS almacenadas, una medida preventiva implica sanitizar y validar minuciosamente todas las entradas del usuario antes de procesarlas y almacenarlas en el almacenamiento del servidor. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109318 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-27783 – HCL BigFix Mobile / Modern Client Management is vulnerable to sensitive information exposure
https://notcve.org/view.php?id=CVE-2021-27783
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed. El archivo PPKG generado por el usuario para Bulk Enroll puede tener expuesta información confidencial sin cifrar • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098586 • CWE-311: Missing Encryption of Sensitive Data •