6.1
CVSSv3

CVE-2023-37520

CVSSv4: NA | CVSSv3: 6.1 | CVSSv2: NA | VMScore: 710 | EPSS: 0.00161 | KEV: Not Included
Published: 21/12/2023 Updated: 21/11/2024

Vulnerability Summary

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.

Vulnerable Product Search on Vulmon Subscribe to Product

hcl software hcl bigfix platform

hcltech bigfix platform

hcltech bigfix platform 11.0.0