CVE-2023-37529

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerability as identified in CVE-2023-37530.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_platform:11.0.0:*:*:*:*:*:*:*

History

17 Dec 2024, 19:31

Type Values Removed Values Added
CPE cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_platform:11.0.0:*:*:*:*:*:*:*
First Time Hcltech bigfix Platform
Hcltech
CWE CWE-79
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0110209 - () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0110209 - Vendor Advisory

21 Nov 2024, 08:11

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de cross-site scripting (XSS) en el componente Web Reports de HCL BigFix Platform posiblemente pueda permitir que un atacante ejecute código javascript malicioso en una página web intentando recuperar información almacenada en cookies. Esta no es la misma vulnerabilidad identificada en CVE-2023-37530.
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0110209 - () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0110209 -

29 Feb 2024, 01:40

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-29 01:40

Updated : 2024-12-17 19:31


NVD link : CVE-2023-37529

Mitre link : CVE-2023-37529

CVE.ORG link : CVE-2023-37529


JSON object : View

Products Affected

hcltech

  • bigfix_platform
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')