CVE-2023-37531: A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform
Published Feb 2, 2024
·Updated
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.
Affected Software
3 affected components
hcltech Bigfix Platform>=9.5<9.5.24
hcltech Bigfix Platform>=10.0.0<10.0.11
hcltech Bigfix Platform=11.0.0
Event History
Feb 2, 2024
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
DescriptionSeverity
Feb 29, 2024
Data Sourced
via NVD·01:40 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-37531?
CVE-2023-37531 is of moderate severity due to its potential to allow execution of malicious JavaScript code.
2
How do I fix CVE-2023-37531?
To fix CVE-2023-37531, you should upgrade HCL BigFix Platform to a version that patches this vulnerability.
3
Which versions of HCL BigFix Platform are affected by CVE-2023-37531?
CVE-2023-37531 affects HCL BigFix Platform versions from 9.5.0 up to 9.5.24, from 10.0.0 up to 10.0.11, and version 11.0.0.
4
What type of vulnerability is CVE-2023-37531?
CVE-2023-37531 is classified as a cross-site scripting (XSS) vulnerability.
5
Can an attacker exploit CVE-2023-37531 without privileged access?
No, an attacker requires privileged access to exploit CVE-2023-37531.