First published: Thu Dec 21 2023(Updated: )
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCLTech Modern Client Management | <3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28025 is considered a medium severity vulnerability that allows for potential stored XSS attacks.
To fix CVE-2023-28025, ensure that all user inputs are properly sanitized and validated prior to processing.
CVE-2023-28025 affects HCLtech Bigfix Modern Client Management versions prior to 3.2.
CVE-2023-28025 is a stored cross-site scripting (XSS) vulnerability due to improper handling of user inputs.
Yes, CVE-2023-28025 can lead to serious security issues such as unauthorized access to sensitive information via the execution of malicious scripts.