VYPR

Platform

by Pega

CVEs (8)

  • CVE-2019-16374CriAug 13, 2020
    risk 0.64cvss 9.8epss 0.02

    Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.

  • CVE-2020-8775HigApr 29, 2020
    risk 0.58cvss 8.9epss 0.01

    Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.

  • CVE-2020-8773HigApr 29, 2020
    risk 0.58cvss 8.9epss 0.01

    The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.

  • CVE-2023-50165HigJan 31, 2024
    risk 0.55cvss 8.5epss 0.00

    Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

  • CVE-2023-50166MedJan 31, 2024
    risk 0.40cvss 6.1epss 0.00

    Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

  • CVE-2023-32089MedOct 18, 2023
    risk 0.30cvss 4.6epss 0.00

    Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description

  • CVE-2023-32088MedOct 18, 2023
    risk 0.30cvss 4.6epss 0.00

    Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation

  • CVE-2023-32087MedOct 18, 2023
    risk 0.30cvss 4.6epss 0.00

    Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation