Security Advisory

CVE-2024-30126

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-07-18 19:17:01
Last updated 2024-10-30 16:24:33
Assigner HCL
CVSS score 4.7
State PUBLISHED

Description

HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.