CVE-2017-17478: XSS
An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context. Designer Studio is the developer workbench for Pega Platform. That XSS payload will execute when other developers visit the affected pages.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-17478?
CVE-2017-17478 is an XSS issue discovered in Designer Studio in Pegasystems Pega Platform versions 7.1.7 to 7.2.2.
How does CVE-2017-17478 impact Pegasystems Pega Platform?
CVE-2017-17478 allows a user with developer credentials to insert malicious code into a text field in Designer Studio, potentially leading to cross-site scripting attacks.
What is the severity of CVE-2017-17478?
CVE-2017-17478 has a severity rating of medium with a CVSS score of 4.8.
How can I fix the CVE-2017-17478 vulnerability?
To fix CVE-2017-17478, upgrade your Pegasystems Pega Platform to a version that is not affected (7.2.3 or later) or apply the necessary security patches provided by Pegasystems.
Where can I find more information about CVE-2017-17478?
You can find more information about CVE-2017-17478 in the Pegasystems Security Bulletin: CVE-2017-17478.