CVE-2023-28025: Hcltech Bigfix Modern Client Management
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.
Affected products
- Hcltech Bigfix Modern Client Management: before 3.2 (fixed in 3.2)
Published 2023-12-21. Last modified 2026-06-17.