CVE-2023-37519
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Dec 21, 2023
Updated: Dec 29, 2023
CWE ID 79
Summary
CVE-2023-37519 refers to an unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This issue lies in the Download Status Report feature of the BigFix Server. An attacker can inject malicious scripts into this report, which gets stored and later executed in a user's web browser when they view the report. This could potentially lead to the theft of sensitive information or unauthorized actions within the user's session.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Hcltech Bigfix Platform
Affected Vendors
- HCL Technologies Ltd.