PT-2020-12620 · Microstrategy · Microstrategy Web

Published

2020-04-02

·

Updated

2020-04-03

·

CVE-2020-11454

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Microstrategy Web version 10.4
Description The issue allows for Stored XSS in the HTML Container and Insert Text features, specifically when creating a new dashboard. To exploit this, an attacker needs access to a shared dashboard or the ability to create a dashboard on the application.
Recommendations For Microstrategy Web version 10.4, consider restricting access to the HTML Container and Insert Text features until a fix is available, and limit the ability to create or share dashboards to trusted users.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11454

Affected Products

Microstrategy Web