A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information.
2024-02-29T01:40:04.740
2025-06-03T19:15:33.213
Modified
CVSSv3.1: 3.0 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | hcltech | bigfix_platform | < 9.5.24 | Yes |
| Application | hcltech | bigfix_platform | < 10.0.11 | Yes |
| Application | hcltech | bigfix_platform | 11.0.0 | Yes |