Loading vulnerability details…
CVSS v3.1
6.5
EPSS
0.34%
Published
Feb 3, 2024
Modified
Jun 3, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:NWeaknesses (CWE)
Affected Products (3)
References (2)