First published: Fri Jul 17 2020(Updated: )
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855&sys_kb_id=971d99ed1b8ed01c086dcbfc0a4bcb6a.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Webui |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4104.
The title of the vulnerability is 'HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module.'
The severity of CVE-2020-4104 is medium with a CVSS score of 5.4.
The affected software is HCL BigFix WebUI.
An attacker can exploit this vulnerability by using stored cross-site scripting (XSS) within the Apps->Software module.