Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-17478

Опубликовано: 27 фев. 2018
Источник: nvd
CVSS3: 4.8
CVSS2: 3.5
EPSS Низкий

Описание

An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context. Designer Studio is the developer workbench for Pega Platform. That XSS payload will execute when other developers visit the affected pages.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:pega:pega_platform:7.1.7:*:*:*:*:*:*:*
cpe:2.3:a:pega:pega_platform:7.1.8:*:*:*:*:*:*:*
cpe:2.3:a:pega:pega_platform:7.1.9:*:*:*:*:*:*:*
cpe:2.3:a:pega:pega_platform:7.1.10:*:*:*:*:*:*:*
cpe:2.3:a:pega:pega_platform:7.2:*:*:*:*:*:*:*
cpe:2.3:a:pega:pega_platform:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:pega:pega_platform:7.2.2:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.0026
Низкий

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
github
больше 3 лет назад

An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context. Designer Studio is the developer workbench for Pega Platform. That XSS payload will execute when other developers visit the affected pages.

EPSS

Процентиль: 49%
0.0026
Низкий

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79