vendor:
PEGA Platform
by:
Pegasystems Inc.
6,1
CVSS
MEDIUM
Missing access control and multiple cross-site scripting
287, 79
CWE
Product Name: PEGA Platform
Affected Version From: PEGA Platform <= 7.2 ML0
Affected Version To: PEGA Platform <= 7.2 ML0
Patch Exists: YES
Related CWE: CVE-2017-11356, CVE-2017-11355
CPE: a:pega:pega_platform
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Missing access control and multiple cross-site scripting vulnerabilities in PEGA Platform
Low privileged users can directly access the administrator resources to download a full compressed file with configurations and files of the platform, a 300MB compressed file was downloaded in a production environment. The application is vulnerable to multiple cross-site scripting vulnerabilities. The application is vulnerable to reflected XSS in the following parameters: pyActivity, pyActivityParam, pyActivityParam.
Mitigation:
Ensure that access control is properly implemented and that all user input is properly sanitized.