Pega Infinity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-8774 - Vulnerability Database
Pega Infinity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-8774
High
Reference:
CVE-2020-8774
Title:
Pega Infinity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the quotActionStringIDquot function.