CVE-2024-10716: Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.

5.9 CVSS

Description

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.

Classification

CVE ID: CVE-2024-10716

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.9

Affected Products

Vendor: Pegasystems

Product: Pega Infinity

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://support.pega.com/support-doc/pega-security-advisory-e24-vulnerability-remediation-note

Timeline