RSS   Vulnerabilities for 'Platform'   RSS

2020-08-13
 
CVE-2019-16374

NVD-CWE-Other
 

 
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.

 
2020-04-29
 
CVE-2020-8775

CWE-79
 

 
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.

 
 
CVE-2020-8773

CWE-79
 

 
The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.

 

 >>> Vendor: PEGA 3 Products
Pega platform
Infinity
Platform


Copyright 2024, cxsecurity.com

 

Back to Top