CVE-2022-27545: HCL BigFix Web Reports authorized users may perform HTML injection.
Published Jul 19, 2022
·Updated
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
Affected Software
2 affected components
hcltech Bigfix Platform>=9.5<=9.5.19
hcltech Bigfix Platform>=10.0<=10.0.6
Event History
Jul 19, 2022
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-27545.
2
What is the title of this vulnerability?
The title of this vulnerability is "BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page."
3
How does this vulnerability affect the software?
This vulnerability affects Hcltech Bigfix Platform versions 9.5.19 and earlier, as well as versions 10.0.6 and earlier.
4
What is the severity of this vulnerability?
The severity of this vulnerability is medium (CVSS score of 5.4).
5
How can this vulnerability be fixed?
Hcltech has provided a patch or update to fix this vulnerability. Please refer to the official support page for detailed instructions.