CVE-2023-50167: XSS
Published Mar 6, 2024
·Updated
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
Affected Software
3 affected components
Pega Platform>=7.1.7<=23.1.1
Pega Pega Platform>=7.1.7<8.8.5
Pega Pega Platform=23.1.1
Event History
Mar 6, 2024
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 25, 57107
Event
via NVD·08:36 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-50167?
CVE-2023-50167 has a moderate severity level due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2023-50167?
To mitigate CVE-2023-50167, update your Pega Platform to a version later than 23.1.1.
3
What systems are affected by CVE-2023-50167?
CVE-2023-50167 affects Pega Platform versions from 7.1.7 to 23.1.1.
4
What type of vulnerability is CVE-2023-50167?
CVE-2023-50167 is an XSS vulnerability related to editing and rendering user HTML content.
5
Is CVE-2023-50167 being actively exploited?
As of now, there is no public evidence that CVE-2023-50167 is actively exploited in the wild.