Impact
The vulnerability is a reflected Cross‑Site Scripting flaw located in a user interface component of Pega Platform. When a high‑privileged user with a developer role interacts with, unsanitized input can be reflected back into a web page, enabling the injection of arbitrary JavaScript. This can lead to client‑side code execution and compromise the confidentiality, integrity, or availability of the information processed by the affected system for the user or anyone who views the crafted response.
Affected Systems
Pegasystems Pega Infinity, versions 8.1.0 through 25.1.2.
Risk and Exploitability
a CVSS score of 4.8 indicates moderate severity; the exploit requires a user with a high‑privileged developer role, limiting the attacker’s opportunities. The EPSS score is below 1%, suggesting a low probability of exploitation in current threat landscapes, and the vulnerability is not listed in CISA KEV. Nevertheless, if an attacker compromises or coerces such a privileged user, the reflected XSS can lead to client‑side code execution within the affected interface, potentially allowing the attacker to hijack the user’s session or manipulate web content for that user.
OpenCVE Enrichment