CVE-2023-50166: XSS
Published Jan 31, 2024
·Updated
Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
Affected Software
1 affected component
Pega Platform>=8.5.4<=8.8.3
Event History
Jan 31, 2024
CVE Published
via MITRE·05:26 PM
Data Sourced
via MITRE·05:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-50166?
CVE-2023-50166 has been rated as a medium severity vulnerability due to its potential impact on web application security.
2
How do I fix CVE-2023-50166?
To fix CVE-2023-50166, it's recommended to upgrade your Pega Platform to a version higher than 8.8.3.
3
What type of vulnerability is CVE-2023-50166?
CVE-2023-50166 is categorized as a Cross-Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2023-50166?
CVE-2023-50166 affects users of the Pega Platform versions ranging from 8.5.4 to 8.8.3.
5
Can an unauthenticated user exploit CVE-2023-50166?
Yes, an unauthenticated user can exploit the XSS vulnerability identified in CVE-2023-50166.