CVE Published: 18/07/2023 |
CVE Updated: 21/10/2024 |
CVE Year: 2023 Source: HCL |
Vendor: HCL Software |
Product: HCL BigFix WebUI Software Distribution Status : PUBLISHED
CVE-2023-28023 Description
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network).
Metrics
CVSS Version: 3.1 |
Base Score: 4.9 MEDIUM Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N