CVE-2021-27781: HCL BigFix Mobile / Modern Client Management is vulnerable to stored cross-site scripting
Published May 27, 2022
·Updated
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
Affected Software
2 affected components
hcltech Bigfix Mobile>=1.0<2.1
hcltech Modern Client Management>=1.0<2.1
Event History
May 27, 2022
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-27781.
2
What is the severity of CVE-2021-27781?
The severity of CVE-2021-27781 is medium.
3
What is the affected software for CVE-2021-27781?
The affected software for CVE-2021-27781 is Hcltech Bigfix Mobile and Hcltech Modern Client Management.
4
How can the Master operator embed a script tag in HTML with an alert pop-up displaying a cookie?
The details of the vulnerability and the exploit method can be found in the reference provided: https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098028
5
What is the CWE ID of CVE-2021-27781?
The CWE ID of CVE-2021-27781 is CWE-79.