PT-2022-8652 · Microstrategy · Microstrategy Web Sdk

Published

2022-05-12

·

Updated

2022-05-23

·

CVE-2020-22984

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MicroStrategy Web SDK versions 10.11 and earlier
Description The issue allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getGoogleExtraConfig task. This is a Cross-Site Scripting (XSS) issue.
Recommendations For MicroStrategy Web SDK versions 10.11 and earlier, update to a version later than 10.11 to resolve the issue. As a temporary workaround, consider restricting access to the getGoogleExtraConfig task to minimize the risk of exploitation. Avoid using the key parameter in the affected task until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-22984

Affected Products

Microstrategy Web Sdk