{"id":"CVE-2020-24815","title":"A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the…","summary":"A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-918"],"vendor":"microstrategy","product":"microstrategy","affected":["microstrategy = 10.4","microstrategy = 2019","microstrategy = 2020"],"published":"2020-11-24","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-24815","references":[{"url":"https://community.microstrategy.com/s/article/Securing-PDF-and-Excel-Export-with-Whitelists?language=en_US","label":"cve@mitre.org"},{"url":"https://triskelelabs.com/extracting-your-aws-access-keys-through-a-pdf-file/","label":"cve@mitre.org"},{"url":"http://microstrategy.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://community.microstrategy.com/s/article/Securing-PDF-and-Excel-Export-with-Whitelists?language=en_US","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://triskelelabs.com/extracting-your-aws-access-keys-through-a-pdf-file/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.01836,"epssPercentile":0.77998,"ingestedAt":"2026-07-05T00:59:25.508Z","exploits":{"github":1,"githubRepos":["https://github.com/darkvirus-7x/exploit-CVE-2020-24815"],"checkedAt":"2026-09-23T07:13:16.641Z"},"exploitAvailable":true,"slug":"CVE-2020-24815","body":"## Overview\n\nA Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the local system via HTML containers embedded in a dossier/dashboard document. NOTE: 10.4., no fix will be released as version will reach end-of-life on 31/12/2020.\n\n## Affected\n\n- `microstrategy = 10.4`\n- `microstrategy = 2019`\n- `microstrategy = 2020`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[{"seq":4477,"id":"CVE-2020-24815","ts":1788887182737,"field":"exploit_available","old":"false","new":"true"},{"seq":3360,"id":"CVE-2020-24815","ts":1788886301683,"field":"exploit_available","old":"true","new":"false"},{"seq":2215,"id":"CVE-2020-24815","ts":1788882971390,"field":"exploit_available","old":"false","new":"true"},{"seq":1244,"id":"CVE-2020-24815","ts":1788882382952,"field":"exploit_available","old":"true","new":"false"},{"seq":358,"id":"CVE-2020-24815","ts":1788881817633,"field":"exploit_available","old":"false","new":"true"}]}