CVE-2023-4843: XSS
Published Sep 8, 2023
·Updated
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.
Affected Software
1 affected component
Pega Pega Platform>=7.1.0<=8.8.3
Event History
Sep 8, 2023
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID for this issue is CVE-2023-4843.
2
What is the severity of CVE-2023-4843?
The severity of CVE-2023-4843 is medium.
3
Which Pega Platform versions are affected by CVE-2023-4843?
Pega Platform versions 7.1 to 8.8.3 are affected by CVE-2023-4843.
4
How does CVE-2023-4843 affect Pega Platform?
CVE-2023-4843 is an HTML Injection issue with a name field utilized in Visual Business Director in Pega Platform versions 7.1 to 8.8.3.
5
Who can modify the name field affected by CVE-2023-4843?
Only an authenticated administrative user can modify the name field affected by CVE-2023-4843.
6
Is there a reference for further information about CVE-2023-4843?
Yes, you can find more information about CVE-2023-4843 in the Pega Platform security advisory.