CVE-2020-8774: XSS
Published Apr 29, 2020
·Updated
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
Affected Software
1 affected component
Pega Pega Platform<8.2.6
Event History
Apr 29, 2020
CVE Published
via MITRE·02:11 PM
Data Sourced
via MITRE·02:11 PM
Description
Frequently Asked Questions
1
What is CVE-2020-8774?
CVE-2020-8774 is a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function of Pega Platform before version 8.2.6.
2
How severe is CVE-2020-8774?
CVE-2020-8774 has a severity rating of 8.8 (high).
3
What software versions are affected by CVE-2020-8774?
Pega Platform versions up to and excluding 8.2.6 are affected by CVE-2020-8774.
4
How can I fix CVE-2020-8774?
To fix CVE-2020-8774, upgrade Pega Platform to version 8.2.6 or above.
5
Where can I find more information about CVE-2020-8774?
More information about CVE-2020-8774 can be found at the following reference: https://community.pega.com/node/1913996