← Back

CVE-2023-37520

nvd nist
Published: Dec 21, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.

Affected (3)

1 product
Bigfix Platform
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Hcltech
From 10.0.0 to 10.0.10
From 9.5 to 9.5.23
Version 11.0.0

References (2)

Timeline

No history available yet.