Vulnerability Description
Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pega | Pega Platform | >= 8.4, <= 8.4.2 |
Related Weaknesses (CWE)
References
- https://jayaramyalla.medium.com/cross-site-scripting-in-pega-cve-2020-23957-16d1ExploitThird Party Advisory
- https://jayaramyalla.medium.com/cross-site-scripting-in-pega-cve-2020-23957-16d1ExploitThird Party Advisory
FAQ
What is CVE-2020-23957?
CVE-2020-23957 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.
How severe is CVE-2020-23957?
CVE-2020-23957 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-23957?
Check the references section above for vendor advisories and patch information. Affected products include: Pega Pega Platform.