Impact
HCL BigFix Mobile is susceptible to reflected Cross‑Site Scripting due to inadequate input validation and output encoding. The flaw allows an attacker to embed arbitrary scripts into the application’s output, potentially enabling session hijacking, data theft, or UI defacement for users who interact with the malformed output.
Affected Systems
The vulnerability affects HCL Software’s HCL BigFix Mobile product. No specific affected versions were listed in the advisory, so any deployment of the product should be treated as potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, and the issue is not cataloged in the CISA KEV list. Attackers would most likely exploit the flaw by delivering malicious input through user‑controlled fields or query parameters, which the application reflects back without proper sanitization. Successful exploitation could compromise user accounts and confidential data within the organization.
OpenCVE Enrichment