CVE-2025-52620: Hcltech Bigfix Saas
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.
Affected products
- Hcltech Bigfix Saas: before 8.1.14 (fixed in 8.1.14)
Published 2025-08-15. Last modified 2026-06-17.