CVE-2025-2161: XSS
Published Apr 14, 2025
·Updated
Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Affected Software
5 affected components
Pega Pega Platform>=7.2.1<=24.2.1
Pega Pega Platform>=7.2.1<8.5.5
Pega Pega Platform>=23.1.0<23.1.4
Pega Pega Platform>=24.1.0<24.1.2
Pega Pega Platform=24.2.0
Event History
Apr 14, 2025
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-2161?
CVE-2025-2161 has been classified as a medium severity XSS vulnerability.
2
How do I fix CVE-2025-2161?
To fix CVE-2025-2161, upgrade your Pega Platform to a version later than 24.2.1.
3
What versions are affected by CVE-2025-2161?
CVE-2025-2161 affects Pega Platform versions from 7.2.1 to 24.2.1.
4
What is the impact of CVE-2025-2161 on web applications?
CVE-2025-2161 can potentially allow attackers to inject malicious scripts into web pages viewed by other users.
5
Is there a workaround for CVE-2025-2161?
Currently, there are no official workarounds for CVE-2025-2161; upgrading the software is recommended.