HTML Injection Vulnerability in Pega Platform by Pegasystems
CVE-2023-4843
4.8MEDIUM
What is CVE-2023-4843?
An HTML Injection vulnerability exists in Pega Platform versions 7.1 to 8.8.3, specifically tied to the name field in Visual Business Director. This field can only be altered by users who are authenticated as administrators, which could allow for the injection of malicious HTML content. If exploited, this could lead to unauthorized data manipulation or other security concerns. Organizations using affected versions are advised to review their security policies and consider applying available remediation measures.
Affected Version(s)
Pega Platform 7.1 < 8.8.4
