PT-2023-21490 · Hcl+1 · Hcl Bigfix Mobile / Modern Client Management+1

CVE-2023-28025

·

Publicado

2023-12-20

·

Atualizado

2023-12-29

CVSS v3.1

6.6

Média

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue allows a Master operator to potentially incorporate an SVG tag into HTML, leading to an alert pop-up that displays a cookie. This is related to stored XSS vulnerabilities. A preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28025

Produtos afetados

Hcl Bigfix Mobile / Modern Client Management
Bigfix Modern Client Management