VYPR
Medium severity4.3NVD Advisory· Published Sep 8, 2023· Updated Jun 17, 2026

CVE-2023-4843

CVE-2023-4843

Description

Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.

Affected products

3
  • Pega/Platform2 versions
    cpe:2.3:a:pega:pega_platform:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pega:pega_platform:*:*:*:*:*:*:*:*range: >=7.1.0,<=8.8.3
    • (no CPE)range: 7.1 to 8.8.3
  • Range: 7.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.