Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q835-q3qm-4v3c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.

Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.

EPSS

Процентиль: 47%
0.0024
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 5 лет назад

Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.

EPSS

Процентиль: 47%
0.0024
Низкий

Дефекты

CWE-79