Description
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
8.1.0 (custom) before Infinity 25.1.0
Credits
Amjad Nayef Qabaha from Integrated Telecom Solutions (INOVAR)
References
support.pega.com/...isory-o25-vulnerability-remediation-note