Description
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
8.1.0 (custom) before Infinity 25.1.2
Credits
Amjad Nayef Qabaha from Integrated Telecom Solutions (INOVAR)
References
support.pega.com/...isory-d26-vulnerability-remediation-note