Learn about CVE-2017-11355, a vulnerability in PEGA Platform 7.2 ML0 allowing remote attackers to inject malicious scripts. Find mitigation steps and long-term security practices here.
Remote attackers can inject arbitrary web script or HTML into PEGA Platform 7.2 ML0 and earlier versions through multiple cross-site scripting (XSS) vulnerabilities.
Understanding CVE-2017-11355
This CVE involves the exploitation of XSS vulnerabilities in PEGA Platform 7.2 ML0 and earlier versions.
What is CVE-2017-11355?
CVE-2017-11355 allows remote attackers to inject malicious web script or HTML by manipulating specific parameters within the PEGA Platform.
The Impact of CVE-2017-11355
Technical Details of CVE-2017-11355
This section provides detailed technical information about the vulnerability.
Vulnerability Description
Multiple XSS vulnerabilities in PEGA Platform 7.2 ML0 and earlier versions enable attackers to inject malicious scripts or HTML code through:
Affected Systems and Versions
Exploitation Mechanism
Attackers exploit the XSS vulnerabilities by manipulating specific parameters within the PEGA Platform, allowing them to inject malicious scripts or HTML.
Mitigation and Prevention
Protecting systems from CVE-2017-11355 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates