Description
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or the (3) pyTableName to the System database schema modification page.
Remediation
References
Related Vulnerabilities
phpMyAdmin Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2020-22278)
Oracle Database Server CVE-2023-22096 Vulnerability (CVE-2023-22096)
WordPress Plugin Product Addons & Fields for WooCommerce Cross-Site Scripting (32.0.5)
WordPress Plugin Relevanssi-A Better Search Cross-Site Scripting (3.5.7.1)