CVE-2020-23957: XSS
Published Dec 15, 2020
·Updated
Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.
Affected Software
1 affected component
Pega Pega Platform>=8.4<=8.4.2
Event History
Dec 15, 2020
CVE Published
via MITRE·08:31 PM
Data Sourced
via MITRE·08:31 PM
Description
Frequently Asked Questions
1
What is CVE-2020-23957?
CVE-2020-23957 is a vulnerability that affects Pega Platform through version 8.4.x, allowing for Cross Site Scripting (XSS) attacks.
2
How does CVE-2020-23957 work?
CVE-2020-23957 works by exploiting the ConnectionID parameter in Pega Platform, typically through a specific pyActivity request.
3
What is the severity of CVE-2020-23957?
CVE-2020-23957 has a severity rating of medium, with a CVSS score of 6.1.
4
What software versions are affected by CVE-2020-23957?
Pega Platform versions between 8.4 and 8.4.2 are affected by CVE-2020-23957.
5
How can I fix CVE-2020-23957?
To fix CVE-2020-23957, it is recommended to upgrade to a version of Pega Platform that is not vulnerable.