A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
No PoCs from references.
- https://github.com/kaje11/CVEs