HCL BigFix Service Management 存在存储型跨站脚本(XSS)漏洞,攻击者可借此在应用程序中注入并持久化恶意脚本。当受害者访问受影响页面时,这些脚本将被执行,从而导致会话劫持以及敏感数据泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL Software | HCL BigFix Service Management | Version 27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66246 | 8.8 HIGH | HCL iControl is affected by multiple security vulnerabilities |
| CVE-2026-67105 | 7.4 HIGH | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-67171 | 5.3 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-67106 | 5.3 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-67104 | 5.3 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2025-31980 | 4.3 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-66247 | 4.3 MEDIUM | iControl不安全CORS策略致敏感数据泄露漏洞 |
| CVE-2026-21833 | 3.7 LOW | HCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnerability (CVE-2 |
| CVE-2026-67172 | 3.7 LOW | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-66253 | 3.1 LOW | HCL iControl is affected by a Session Timeout vulnerability |
| CVE-2026-66249 | 3.1 LOW | HCL iControl is affected by a Missing Secure Attribute vulnerability |
| CVE-2026-66248 | 3.1 LOW | HCL iControl is affected by an Improper Error Handling vulnerability |
| CVE-2026-56599 | 2.2 LOW | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
No comments yet