4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Description
HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.
Basic Information
ID
CVE-2025-52620
Source
HCL
Published
Aug 15, 2025 at 22:47
Affected Product
Vendor
HCL Software
Product
BigFix SaaS Remediate
Version
< 8.1.14
Affected Versions
HCL Software BigFix SaaS Remediate < 8.1.14