CVE-2023-37530

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_platform:11.0.0:*:*:*:*:*:*:*

History

17 Dec 2024, 19:31

Type Values Removed Values Added
First Time Hcltech bigfix Platform
Hcltech
CPE cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_platform:11.0.0:*:*:*:*:*:*:*
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0110209 - () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0110209 - Vendor Advisory
CWE CWE-79

21 Nov 2024, 08:11

Type Values Removed Values Added
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0110209 - () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0110209 -
Summary
  • (es) Una vulnerabilidad de cross-site scripting (XSS) en el componente Web Reports de HCL BigFix Platform posiblemente pueda permitir que un atacante ejecute código javascript malicioso en una página web intentando recuperar información almacenada en cookies.

29 Feb 2024, 01:40

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-29 01:40

Updated : 2024-12-17 19:31


NVD link : CVE-2023-37530

Mitre link : CVE-2023-37530

CVE.ORG link : CVE-2023-37530


JSON object : View

Products Affected

hcltech

  • bigfix_platform
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')