CVE-2023-37527: A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37527?
The severity of CVE-2023-37527 is rated as high due to the potential impact of executing malicious JavaScript code.
How do I fix CVE-2023-37527?
To fix CVE-2023-37527, update the HCL BigFix Platform to the latest patched version released by HCL Technologies.
What are the affected versions related to CVE-2023-37527?
CVE-2023-37527 affects HCL BigFix Platform versions from 9.5.0 to 9.5.24, and between 10.0.0 and 10.0.11, as well as version 11.0.0.
What type of vulnerability is CVE-2023-37527?
CVE-2023-37527 is classified as a reflected cross-site scripting (XSS) vulnerability.
Who can be affected by CVE-2023-37527?
Users of HCL BigFix Platform who access web reports may be affected by CVE-2023-37527 if they are exposed to malicious content.