Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://community.pega.com/knowledgebase/products/platform/release-notes | release notes vendor advisory |
https://community.pega.com/knowledgebase/products/platform/resolved-issues?q=527502 | vendor advisory |