ZeroHour

CVE-2020-22985

CVSS 3.1
6.1 medium
EPSS
2%p74
Published
()
Modified
Description

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

Vendors
microstrategy
Products
microstrategy web sdk
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.