CVE-2023-28019: Hcltech Bigfix Webui

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.

Affected products

  • Hcltech Bigfix Webui: before 14 (fixed in 14)

Published 2023-07-18. Last modified 2026-06-17.