ZeroHour

CVE-2023-4843

CVSS 3.1
4.8 medium
EPSS
<1%p27
Published
()
Modified
Description

Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.

Vendors
pega
Products
pega platform
Weakness
CWE-74, CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.