Home
MEDIUM: 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:NDefault status
unaffected
7.1.0 (custom) before Infinity 24.2.3
affected
Description
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
7.1.0 (custom) before Infinity 24.2.3
Credits
Louis Sohier of ENGIE IT Offensive Cybersecurity Team
References
support.pega.com/...isory-g25-vulnerability-remediation-note