High severity7.7NVD Advisory· Published Dec 21, 2023· Updated Jun 17, 2026
CVE-2023-37520
CVE-2023-37520
Description
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.
Affected products
4cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*range: >=9.5,<9.5.23
- cpe:2.3:a:hcltech:bigfix_platform:11.0.0:*:*:*:*:*:*:*
- Range: = 9.5.12.68
- Range: 9.5.x, 10.0.x, 11.0.0
Patches
Vulnerability mechanics
References
1- support.hcltechsw.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.