VYPR
Medium severity6.5NVD Advisory· Published Feb 3, 2024· Updated Jun 17, 2026

CVE-2023-37528

CVE-2023-37528

Description

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.

Affected products

4
  • cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*range: >=9.5,<9.5.24
    • cpe:2.3:a:hcltech:bigfix_platform:11.0.0:*:*:*:*:*:*:*
  • HCL Software/BigFix Platformllm-create2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 9.5 - 9.5.23, 10 - 10.0.9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.