CVE-2025-62184: Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component.
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62184?
CVE-2025-62184 is considered a high severity vulnerability due to its potential for enabling stored cross-site scripting attacks.
How do I fix CVE-2025-62184?
To fix CVE-2025-62184, upgrade to a patched version of Pega Platform that is beyond version 25.1.0.
What components of Pega Platform are affected by CVE-2025-62184?
CVE-2025-62184 affects the user interface components of Pega Platform versions 8.1.0 through 25.1.0.
Can CVE-2025-62184 be exploited without authentication?
Exploitation of CVE-2025-62184 requires an administrative account, making it more challenging to exploit.
What types of attacks can CVE-2025-62184 facilitate?
CVE-2025-62184 can facilitate malicious scripts being stored and executed, leading to data theft or session hijacking.