Description
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2023-33129 Vulnerability (CVE-2023-33129)
Drupal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-25277)
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2016-0284)
WordPress Plugin YITH WooCommerce Ajax Search Security Bypass (1.6.9)
WordPress Plugin WP e-Commerce-Store Exporter Privilege Escalation (1.6.6)