CVE-2022-27545Medium· 4.6▾ SunlitBigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
bigfix_platform >= 9.5, <= 9.5.19bigfix_platform >= 10.0, <= 10.0.6Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-27544Medium· 5.0BigFix Web Reports authorized users may see SMTP credentials in clear text.
CVE-2025-52624Medium· 5.4A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other inject…
CVE-2025-0277Medium· 6.5HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP)
CVE-2025-0276Medium· 6.5HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP)
CVE-2026-56589High· 7.2HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page…
CVE-2025-52653High· 7.6HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application