CVE-2024-12211: XSS
Published Jan 13, 2025
·Updated
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
Affected Software
4 affected components
Pega Pega Platform>=8.1<24.2.0
Pega Pega Platform>=8.1<23.1.4
Pega Pega Platform>=24.1.0<24.1.2
Pega Pega Platform=24.2.0
Event History
Jan 13, 2025
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-12211?
CVE-2024-12211 is classified as a high severity vulnerability due to the potential impact of stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-12211?
To fix CVE-2024-12211, update Pega Platform to a version newer than 24.2.0.
3
What is the impact of CVE-2024-12211 on Pega Platform?
The impact of CVE-2024-12211 includes the possibility of attackers executing arbitrary JavaScript in user profiles, which can lead to data theft or session hijacking.
4
Which versions of Pega Platform are affected by CVE-2024-12211?
CVE-2024-12211 affects Pega Platform versions from 8.1 up to but not including 24.2.0.
5
Is CVE-2024-12211 a known issue in Pega security advisories?
Yes, CVE-2024-12211 has been acknowledged in Pega security advisories regarding vulnerability management.