PT-2023-21490 · Hcl+1 · Hcl Bigfix Mobile / Modern Client Management+1

Published

2023-12-20

·

Updated

2023-12-29

·

CVE-2023-28025

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue allows a Master operator to potentially incorporate an SVG tag into HTML, leading to an alert pop-up that displays a cookie. This is related to stored XSS vulnerabilities. A preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-28025

Affected Products

Hcl Bigfix Mobile / Modern Client Management
Bigfix Modern Client Management