First published: Fri Feb 02 2024(Updated: )
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL BigFix Platform | >=9.5<9.5.24 | |
HCL BigFix Platform | >=10.0.0<10.0.11 | |
HCL BigFix Platform | =11.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-37527 is rated as high due to the potential impact of executing malicious JavaScript code.
To fix CVE-2023-37527, update the HCL BigFix Platform to the latest patched version released by HCL Technologies.
CVE-2023-37527 affects HCL BigFix Platform versions from 9.5.0 to 9.5.24, and between 10.0.0 and 10.0.11, as well as version 11.0.0.
CVE-2023-37527 is classified as a reflected cross-site scripting (XSS) vulnerability.
Users of HCL BigFix Platform who access web reports may be affected by CVE-2023-37527 if they are exposed to malicious content.