First published: Thu Dec 21 2023(Updated: )
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Platform | >=9.5<9.5.23 | |
Hcltech Bigfix Platform | >=10.0.0<10.0.10 | |
Hcltech Bigfix Platform | =11.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37519 is classified as an unauthenticated stored cross-site scripting (XSS) vulnerability.
To fix CVE-2023-37519, ensure you are using an updated version of the HCL BigFix Platform that is not affected by this vulnerability.
CVE-2023-37519 affects HCL BigFix Platform versions between 9.5.0 and 9.5.23, as well as 10.0.0 to 10.0.10, and 11.0.0.
CVE-2023-37519 enables attackers to execute unauthenticated stored XSS attacks through the Download Status Report.
You can test for CVE-2023-37519 by checking the Download Status Report for any potential XSS payloads that could be stored and executed.