CVE-2023-37523: HCL BigFix OSD Bare Metal Server WebUI is affected by missing or insecure tags
Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability description for CVE-2023-37523?
CVE-2023-37523 is a vulnerability in the HCL BigFix Bare OSD Metal Server WebUI versions 311.19 or lower that could allow an attacker to execute a malicious script in the user's browser due to missing or insecure tags.
What versions of HCL BigFix Bare OSD Metal Server WebUI are affected by CVE-2023-37523?
HCL BigFix Bare OSD Metal Server WebUI versions 311.19 or lower are affected by CVE-2023-37523.
What is the potential impact of CVE-2023-37523?
The potential impact of CVE-2023-37523 is that it could allow attackers to execute arbitrary scripts in the user's browser, leading to unauthorized access or data compromise.
How do I fix CVE-2023-37523?
To fix CVE-2023-37523, update the HCL BigFix Bare OSD Metal Server WebUI to a version higher than 311.19 that addresses the insecure tags issue.
What kind of attack does CVE-2023-37523 enable?
CVE-2023-37523 enables cross-site scripting (XSS) attacks by allowing malicious scripts to be executed in the context of the user's browser.