HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0123330