Description
Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.
Problem types
CWE-434: Unrestricted Upload of File with Dangerous Type
Product status
8.7.0 (custom) before Infinity 25.1.1
Credits
Daniel Dorego from AFLAC
References
support.pega.com/...isory-l25-vulnerability-remediation-note