Skip to content
Noroxi

microstrategy records

20 published records for vendor microstrategy.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

20 records
  • MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../.

    CriticalCVSS 9.8No exploitEPSS 2%

    microstrategy · enterprise managerMay 11, 2022

  • CVE-2018-6885
    39Monitor

    An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11.

    CriticalCVSS 9.8No exploitEPSS 1%

    microstrategy · web servicesMay 14, 2019

  • Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStr

    HighCVSS 7.5Proof of conceptEPSS 18%

    microstrategy · microstrategy webApr 2, 2020

  • main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF.

    HighCVSS 8.8No exploitEPSS 1%

    microstrategy · microstrategyDec 28, 2018

  • A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers

    HighCVSS 8.1No exploitEPSS 2%

    microstrategy · microstrategy webMay 13, 2022

  • The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files w

    HighCVSS 7.2No exploitEPSS 3%

    microstrategy · microstrategy webApr 2, 2020

  • A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allo

    MediumCVSS 6.5Proof of conceptEPSS 2%

    microstrategy · microstrategyNov 24, 2020

  • Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability v

    MediumCVSS 6.1Proof of conceptEPSS 8%

    microstrategy · microstrategy webNov 1, 2018

  • Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.

    MediumCVSS 6.1Proof of conceptEPSS 5%

    microstrategy · microstrategy libraryNov 14, 2019

  • Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability v

    MediumCVSS 6.1Proof of conceptEPSS 2%

    microstrategy · microstrategy webNov 1, 2018

  • Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote a

    MediumCVSS 4.3Proof of conceptEPSS 23%

    microstrategy · microstrategy webNov 1, 2018

  • Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi

    MediumCVSS 6.1No exploitEPSS 2%

    microstrategy · microstrategy web sdkMay 12, 2022

  • Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi

    MediumCVSS 6.1No exploitEPSS 2%

    microstrategy · microstrategy web sdkMay 12, 2022

  • Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi

    MediumCVSS 6.1No exploitEPSS 2%

    microstrategy · microstrategy web sdkMay 12, 2022

  • Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi

    MediumCVSS 6.1No exploitEPSS 1%

    microstrategy · microstrategy web sdkMay 12, 2022

  • In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.

    MediumCVSS 6.1Proof of conceptEPSS 1%

    microstrategy · microstrategy webJul 19, 2019

  • In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.

    MediumCVSS 6.1Proof of conceptEPSS 1%

    microstrategy · microstrategy webJul 17, 2019

  • Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStr

    MediumCVSS 5.3No exploitEPSS 3%

    microstrategy · microstrategy webApr 2, 2020

  • Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation o

    MediumCVSS 5.4No exploitEPSS 1%

    microstrategy · microstrategy webApr 2, 2020

  • Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases.

    MediumCVSS 4.3No exploitEPSS 1%

    microstrategy · microstrategy webApr 2, 2020