Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2020-22987

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.
Attacker Value
Unknown

CVE-2020-22986

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task.
Attacker Value
Unknown

CVE-2020-22985

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.
Attacker Value
Unknown

CVE-2020-22984

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task.