ZeroHour

CVE-2020-22983

CVSS 3.1
8.1 high
EPSS
2%p83
Published
()
Modified
Description

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

Vendors
microstrategy
Products
microstrategy web
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.