PT-2022-8654 · Microstrategy · Microstrategy Web Sdk

Published

2022-05-12

·

Updated

2022-05-23

·

CVE-2020-22986

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MicroStrategy Web SDK versions 10.11 and earlier
Description The issue allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task. This is a Cross-Site Scripting (XSS) issue.
Recommendations For MicroStrategy Web SDK versions 10.11 and earlier, avoid using the searchString parameter in the wikiScrapper task until a fix is available. As a temporary workaround, consider restricting access to the wikiScrapper task to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-22986

Affected Products

Microstrategy Web Sdk