First published: Mon May 09 2022(Updated: )
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Mobile | >=1.0<2.1 | |
Hcltech Modern Client Management | >=1.0<2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-27781.
The severity of CVE-2021-27781 is medium.
The affected software for CVE-2021-27781 is Hcltech Bigfix Mobile and Hcltech Modern Client Management.
The details of the vulnerability and the exploit method can be found in the reference provided: https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098028
The CWE ID of CVE-2021-27781 is CWE-79.