Looking for the vulnerability index of Invicti's legacy products?
Pega Infinity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2023-4843 - Vulnerability Database

Pega Infinity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2023-4843

Medium
Reference: CVE-2023-4843
Title: Pega Infinity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director however this field can only be modified by an authenticated administrative user.