CVE-2023-37527

EUVD-2023-41414
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page. 
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
hcltechbigfix_platform
9.5 ≤
𝑥
< 9.5.24
hcltechbigfix_platform
10.0.0 ≤
𝑥
< 10.0.11
hcltechbigfix_platform
11.0.0
𝑥
= Vulnerable software versions