Executive brief
HCL BigFix Mobile is a mobile management application used by enterprises to deploy and manage software across devices. The application fails to properly validate and encode user-controlled input before displaying it in web pages, allowing an attacker to inject malicious JavaScript code that executes in a victim's browser. This could lead to credential theft, session hijacking, or compromise of the management interface itself.
Technical details
The vulnerability is a Reflected Cross-Site Scripting (XSS) flaw caused by insufficient input validation and output encoding in HCL BigFix Mobile. An attacker can craft a malicious URL containing JavaScript payload and trick a user into clicking it; the unvalidated input is then reflected back in the HTTP response and executed in the user's browser. No authentication is required to exploit this vulnerability, and it is accessible over the network. Successful exploitation allows the attacker to perform actions on behalf of the victim, steal session tokens, or redirect users to phishing sites. Patches are available from HCL Software.
Affected products
- HCL BigFix Mobile
Timeline
- 2026-08-10: disclosed