Low severity3.0NVD Advisory· Published Feb 2, 2024· Updated Jun 17, 2026
CVE-2024-23553
CVE-2024-23553
Description
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
Affected products
4cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*range: >=9.5,<9.5.24
- cpe:2.3:a:hcltech:bigfix_platform:11.0.0:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 9.5 - 9.5.23, 10 - 10.0.10
Patches
Vulnerability mechanics
References
1- support.hcltechsw.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.