Impact
This vulnerability is a stored cross‑site scripting flaw in a user interface component of Pega Platform. The flaw, identified as CWE‑79, allows a user with high privileged developer role to inject malicious scripts that persist in the system.
Affected Systems
Pegasystems Pega Infinity Platform versions 8.1.0 through 25.1.2.
Risk and Exploitability
The CVSS score of 4.6 classifies the risk as medium, while an EPSS score of <1% indicates a very low current exploitation likelihood. The vulnerability is not in the CISA KEV catalog. Exploitation requires possession of a high‑privileged developer account or compromise of such an account, so the attack vector is limited to users with those permissions. Because the payload runs in the victim’s browser, the threat is primarily directed at users who interact with the affected component, and the overall risk remains moderate.
OpenCVE Enrichment