CVE-2023-28025

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
21/12/2023
Last modified:
29/12/2023

Description

Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage. <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:bigfix_modern_client_management:*:*:*:*:*:*:*:* 3.2 (excluding)