CVE-2025-2160: XSS
Published Apr 14, 2025
·Updated
Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Affected Software
5 affected components
Pega Platform>=8.4.3<=24.2.1
Pega Pega Platform>=8.4.3<8.5.5
Pega Pega Platform>=23.1.0<23.1.4
Pega Pega Platform>=24.1.0<24.1.2
Pega Pega Platform=24.2.0
Event History
Apr 14, 2025
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-2160?
CVE-2025-2160 has a severity rating that indicates it poses a risk due to its XSS vulnerability in the Pega Platform.
2
How do I fix CVE-2025-2160?
To fix CVE-2025-2160, it is recommended to upgrade Pega Platform to a version later than 24.2.1.
3
Which versions of Pega Platform are affected by CVE-2025-2160?
CVE-2025-2160 affects Pega Platform versions from 8.4.3 to 24.2.1.
4
What type of vulnerability is CVE-2025-2160?
CVE-2025-2160 is classified as a Cross-Site Scripting (XSS) vulnerability.
5
What can attackers achieve with CVE-2025-2160?
Attackers can exploit CVE-2025-2160 to execute malicious scripts in the context of a user's session.