XSS Vulnerability in Pega Platform Affects Unauthenticated Users
CVE-2023-50166
6.1MEDIUM
What is CVE-2023-50166?
The Pega Platform versions ranging from 8.5.4 to 8.8.3 are susceptible to a Cross-Site Scripting (XSS) vulnerability that allows unauthenticated users to exploit a vulnerability via the redirect parameter. This could potentially allow attackers to inject malicious scripts into web pages viewed by other users, leading to unauthorized access to users' session information or manipulation of web sessions.
Affected Version(s)
Pega Platform 8.5.4 <= 8.8.3
