VulnSea

microstrategy has 6 CVEs on record between 2020 and 2022. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (4). Most affected products: microstrategy_web_sdk (4), microstrategy (1), microstrategy_web (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
0 prev 0

Weakness classes

Products

  • microstrategy_web_sdk 4
  • microstrategy 1
  • microstrategy_web 1
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

microstrategy vulnerabilities

CVEs affecting microstrategy, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2020-22983High· 8.1
4y ago

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL …

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL …

Twilightmicrostrategy · microstrategy_webEPSS 2.4%via NVD
CVE-2020-22987Medium· 6.1
4y ago

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.

Sunlitmicrostrategy · microstrategy_web_sdkEPSS 1.5%via NVD
CVE-2020-22986Medium· 6.1
4y ago

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task.

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task.

Sunlitmicrostrategy · microstrategy_web_sdkEPSS 1.6%via NVD
CVE-2020-22985Medium· 6.1
4y ago

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

Sunlitmicrostrategy · microstrategy_web_sdkEPSS 1.6%via NVD
CVE-2020-22984Medium· 6.1
4y ago

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task.

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task.

Sunlitmicrostrategy · microstrategy_web_sdkEPSS 1.6%via NVD
CVE-2020-24815Medium· 6.5PoC
5y ago

A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the…

A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the…

Twilightmicrostrategy · microstrategyEPSS 1.8%via NVD
microstrategy vulnerabilities (CVEs) · VulnSea