Impact
The vulnerability is a cross‑site scripting flaw that allows an attacker to inject unsanitized JavaScript into the HCL BigFix Service Management web interface. If a victim navigates to a crafted page or receives manipulated content, the malicious script executes in that user’s browser. This attack vector enables the attacker to hijack the user’s session, take over the account, and perform any authorized actions on the victim’s behalf.
Affected Systems
HCL Software’s BigFix Service Management product is affected. The advisory does not specify exact versions, so all releases that contain the vulnerable code should be examined for the flaw.
Risk and Exploitability
The CVSS base score of 7.6 indicates high severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to lure a user to a maliciously crafted page or convince the user to load untrusted content, meaning the attack relies on user interaction and social engineering.
OpenCVE Enrichment