CVE-2024-10716: XSS
Published Dec 5, 2024
·Updated
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.
Affected Software
5 affected components
Pega Pega Platform>=8.1<24.2.0
Pega Infinity>=8.1<=8.8.5
Pega Infinity>=23.1<23.1.4
Pega Infinity>=24.1<24.1.2
Pega Infinity=24.2
Event History
Dec 5, 2024
CVE Published
via MITRE·03:28 PM
Data Sourced
via MITRE·03:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-10716?
CVE-2024-10716 is classified as a high severity XSS vulnerability affecting Pega Platform.
2
How do I fix CVE-2024-10716?
To fix CVE-2024-10716, upgrade to Pega Platform version 24.2.1 or later.
3
What versions of Pega Platform are affected by CVE-2024-10716?
Pega Platform versions from 8.1 to 24.2.0 are affected by CVE-2024-10716.
4
What is the impact of CVE-2024-10716?
The impact of CVE-2024-10716 is that it allows unauthorized users to execute malicious scripts in the context of a legitimate user.
5
Is there a workaround for CVE-2024-10716?
There are no specific workarounds for CVE-2024-10716; upgrading to a patched version is recommended.