5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Description
A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type restrictions during the upload process. An attacker may exploit this flaw to upload malicious or unauthorized files, such as scripts, executables, or web shells, by bypassing client-side or server-side validation mechanisms.
Basic Information
ID
CVE-2025-31979
Source
HCL
Published
Aug 28, 2025 at 17:06
Modified
Aug 28, 2025 at 17:14
Affected Product
Vendor
HCL Software
Product
BigFix Service Management (SM)
Version
23
Affected Versions
HCL Software BigFix Service Management (SM) 23