CVE-2024-6702: XSS
Published Sep 12, 2024
·Updated
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
Affected Software
1 affected component
PEGA Infinity>=8.1<24.1.3
Event History
Sep 12, 2024
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-6702?
CVE-2024-6702 is classified as a medium severity vulnerability due to its potential for HTML injection.
2
Which Pega Platform versions are affected by CVE-2024-6702?
CVE-2024-6702 affects Pega Platform versions from 8.1 to 24.1.2.
3
How do I fix CVE-2024-6702?
To remediate CVE-2024-6702, update your Pega Platform to version 24.1.3 or later.
4
What impact does CVE-2024-6702 have on the Pega Platform?
CVE-2024-6702 can allow an attacker to execute HTML injection attacks, potentially compromising user data.
5
Is there a workaround for CVE-2024-6702?
Currently, the recommended approach to mitigate CVE-2024-6702 is to upgrade to the patched version, as no specific workaround is provided.