PT-2022-8654 · Microstrategy · Microstrategy Web Sdk
Published
2022-05-12
·
Updated
2022-05-23
·
CVE-2020-22986
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MicroStrategy Web SDK versions 10.11 and earlier
Description
The issue allows remote unauthenticated attackers to execute arbitrary code via the
searchString parameter to the wikiScrapper task. This is a Cross-Site Scripting (XSS) issue.Recommendations
For MicroStrategy Web SDK versions 10.11 and earlier, avoid using the
searchString parameter in the wikiScrapper task until a fix is available. As a temporary workaround, consider restricting access to the wikiScrapper task to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microstrategy Web Sdk