High severity7.7NVD Advisory· Published Dec 21, 2023· Updated Jun 17, 2026
CVE-2023-37519
CVE-2023-37519
Description
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server.
Affected products
4cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*range: >=9.5,<9.5.23
- cpe:2.3:a:hcltech:bigfix_platform:11.0.0:*:*:*:*:*:*:*
- Range: 9.5.x, 10.0.x
Patches
Vulnerability mechanics
References
1- support.hcltechsw.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.