CVE-2023-28023

A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:bigfix_webui:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 4.9
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0106123 - () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0106123 -

01 Aug 2023, 01:15

Type Values Removed Values Added
Summary HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information. A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 
References
  • {'url': 'https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0105904', 'name': 'https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0105904', 'tags': [], 'refsource': 'MISC'}
  • (MISC) https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0106123 -

31 Jul 2023, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0106123', 'name': 'https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0106123', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • (MISC) https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0105904 -
Summary A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network).  HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.

27 Jul 2023, 04:06

Type Values Removed Values Added
CPE cpe:2.3:a:hcltech:bigfix_webui:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-352
References (MISC) https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0106123 - (MISC) https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0106123 - Vendor Advisory

18 Jul 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-18 20:15

Updated : 2024-11-21 07:53


NVD link : CVE-2023-28023

Mitre link : CVE-2023-28023

CVE.ORG link : CVE-2023-28023


JSON object : View

Products Affected

hcltech

  • bigfix_webui
CWE
CWE-352

Cross-Site Request Forgery (CSRF)