CVE-2020-23957
15.12.2020, 21:15
Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.
Vendor | Product | Version |
---|---|---|
pega | pega_platform | 8.4 ≤ 𝑥 ≤ 8.4.2 |
𝑥
= Vulnerable software versions