CVE-2023-32088: XSS
Published Oct 18, 2023
·Updated
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation
Affected Software
2 affected components
Pega Platform>=8.1.0<8.7.5
Pega Platform>=8.8.0<8.8.3
Event History
Oct 18, 2023
CVE Published
via MITRE·11:42 AM
Data Sourced
via MITRE·11:42 AM
DescriptionSeverityWeakness
Data Sourced
12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the XSS issue in Pega Platform?
The vulnerability ID is CVE-2023-32088.
2
What version of Pega Platform is affected by this XSS issue?
Pega Platform versions 8.1 to Infinity 23.1.0 are affected.
3
What is the severity of CVE-2023-32088?
The severity of CVE-2023-32088 is medium with a CVSS score of 6.1.
4
How does this vulnerability impact Pega Platform?
This vulnerability allows for cross-site scripting (XSS) attacks with ad-hoc case creation in affected Pega Platform versions.
5
How can I fix the XSS issue in Pega Platform?
To fix the XSS issue, you should upgrade Pega Platform to a version that is not affected by the vulnerability.