MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or the (3) pyTableName to the System database schema modification page
Published Aug 2, 2017
6.1
MEDIUMCVSS 3.0
EPSS 2.90%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.