CVE-2023-37520
HCL BigFix Platform is affected by Unathenticated Stored Cross-Site Scripting (XSS)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.
Vulnerabilidad de Cross-Site Scripting (XSS) almacenado no autenticada identificada en BigFix Server versión 9.5.12.68, lo que permite una posible filtración de datos. Esta vulnerabilidad XSS se encuentra en el Gather Status Report, que proporciona BigFix Relay.
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-07-06 CVE Reserved
- 2023-12-21 CVE Published
- 2024-08-02 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109376 | 2023-12-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hcltech Search vendor "Hcltech" | Bigfix Platform Search vendor "Hcltech" for product "Bigfix Platform" | >= 9.5 < 9.5.23 Search vendor "Hcltech" for product "Bigfix Platform" and version " >= 9.5 < 9.5.23" | - |
Affected
| ||||||
Hcltech Search vendor "Hcltech" | Bigfix Platform Search vendor "Hcltech" for product "Bigfix Platform" | >= 10.0.0 < 10.0.10 Search vendor "Hcltech" for product "Bigfix Platform" and version " >= 10.0.0 < 10.0.10" | - |
Affected
| ||||||
Hcltech Search vendor "Hcltech" | Bigfix Platform Search vendor "Hcltech" for product "Bigfix Platform" | 11.0.0 Search vendor "Hcltech" for product "Bigfix Platform" and version "11.0.0" | - |
Affected
|