Cross-Site Scripting Vulnerability in Pega Platform
CVE-2023-32089
4.6MEDIUM
What is CVE-2023-32089?
The Pega Platform, spanning versions 8.1 to 8.8.2, is susceptible to an XSS vulnerability that affects the handling of pin descriptions. This security flaw allows attackers to inject malicious scripts, potentially compromising user sessions and sensitive data. It is imperative for users of the affected versions to review the security advisory and implement recommended mitigations to safeguard their applications.
Affected Version(s)
Pega Platform 8.1 < 8.8.3
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Reuben Seymour, Amber Hamlet and Skyler Knecht from the Adversarial Security Practice at Navy Federal Credit Union
