Required CVE Record Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or the (3) pyTableName to the System database schema modification page.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- https://pdn.pega.com/pegasystems-security-bulletin-cve-2017-11355-and-cve-2017-11356/pegasystems-security-bulletin-cve x_transferred
- exploit-db.com: 42335 exploitx_transferred
- seclists.org: 20170717 PEGA Platform <= 7.2 ML0 - Multiple vulnerabilities mailing-listx_transferred