Unrated severityNVD Advisory· Published Feb 2, 2024· Updated Jun 3, 2025
A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform
CVE-2023-37527
Description
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.
Affected products
1- Range: 9.5 - 9.5.23, 10 - 10.0.10
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.