CVE-2023-28025
An HTML injection vulnerability can affect HCL BigFix Mobile / Modern Client Management
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.
Debido a esta vulnerabilidad, el operador maestro podrĂa potencialmente incorporar una etiqueta SVG en HTML, lo que generarĂa una ventana emergente de alerta que muestra una cookie. Para mitigar las vulnerabilidades XSS almacenadas, una medida preventiva implica sanitizar y validar minuciosamente todas las entradas del usuario antes de procesarlas y almacenarlas en el almacenamiento del servidor.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-03-10 CVE Reserved
- 2023-12-21 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109318 | 2023-12-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hcltech Search vendor "Hcltech" | Bigfix Modern Client Management Search vendor "Hcltech" for product "Bigfix Modern Client Management" | < 3.2 Search vendor "Hcltech" for product "Bigfix Modern Client Management" and version " < 3.2" | - |
Affected
|