Impact
Pega Platform versions 23.1.0 through 25.1.3 contain a stored cross‑site scripting flaw in a user interface component. The flaw requires a user with high privileged developer role to inject malicious script data that is later rendered in the browser of other users. Successful exploitation could allow an attacker to execute arbitrary JavaScript in the victim’s browser, potentially enabling session hijacking, credential theft, or defacement.
Affected Systems
Pegasystems Pega Infinity is affected. The vulnerability spans releases 23.1.0 to 25.1.3. No other vendors or products were identified in the CNA data.
Risk and Exploitability
CVSS score of 4.6 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV. Attack requires a developer role, limiting the attack surface to users with that role. Because the flaw resides in a UI component, exploitation generally requires manual injection by a developer; it is unlikely to be automated without privileged access.
OpenCVE Enrichment