Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-31963.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "4.2" } ] } ]