CVE-2025-8681
Estado: AnalizadaMedia (5.4)—
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-8681",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-8681",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-09-11T14:27:19.118508Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@pega.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 1.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "security@pega.com",
"affectedData": [
{
"vendor": "Pegasystems",
"product": "Pega Infinity",
"versions": [
{
"status": "affected",
"version": "7.1.0",
"lessThan": "Infinity 24.2.3",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-09-10T16:15:42.130",
"references": [
{
"url": "https://support.pega.com/support-doc/pega-security-advisory-g25-vulnerability-remediation-note",
"tags": [
"Vendor Advisory"
],
"source": "security@pega.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@pega.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role."
},
{
"lang": "es",
"value": "Las versiones de Pega Platform 7.1.0 hasta Infinity 24.2.2 están afectadas por un problema de XSS Almacenado en un componente de la interfaz de usuario. Requiere un usuario con altos privilegios y rol de desarrollador."
}
],
"lastModified": "2026-09-26T00:10:00.127",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pega:pega_platform:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3E025E37-EFCE-4BA5-8517-B34D445731B6",
"versionEndExcluding": "23.1.5",
"versionStartIncluding": "7.1.0"
},
{
"criteria": "cpe:2.3:a:pega:pega_platform:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12DCD9B7-08F4-43D1-B361-2EC496D5F7C9",
"versionEndExcluding": "24.1.3",
"versionStartIncluding": "24.1.0"
},
{
"criteria": "cpe:2.3:a:pega:pega_platform:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58EC0973-3139-4B4D-BE29-1911F0982C75",
"versionEndExcluding": "24.2.2",
"versionStartIncluding": "24.2.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@pega.com"
}