Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2024-43612

Disclosure Date: October 08, 2024 (last updated October 22, 2024)
Power BI Report Server Spoofing Vulnerability
Attacker Value
Unknown

CVE-2024-43481

Disclosure Date: October 08, 2024 (last updated October 17, 2024)
Power BI Report Server Spoofing Vulnerability
Attacker Value
Unknown

CVE-2023-21806

Disclosure Date: February 14, 2023 (last updated January 11, 2025)
Power BI Report Server Spoofing Vulnerability
Attacker Value
Unknown

CVE-2021-41372

Disclosure Date: November 10, 2021 (last updated November 28, 2024)
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities together, an attacker is able to upload malicious Power BI templates files to the server using the victim's session and run scripts in the security context of the user and perform privilege escalation in case the victim has admin privileges when the victim access one of the HTML files present in the malicious Power BI template uploaded. The security update addresses the vulnerability by helping to ensure that Power BI Report Server properly sanitize file uploads.
0
Attacker Value
Unknown

CVE-2021-31984

Disclosure Date: July 14, 2021 (last updated November 28, 2024)
Power BI Remote Code Execution Vulnerability
0
Attacker Value
Unknown

CVE-2021-26859

Disclosure Date: March 11, 2021 (last updated November 28, 2024)
Microsoft Power BI Information Disclosure Vulnerability
0
Attacker Value
Unknown

CVE-2020-1173

Disclosure Date: May 21, 2020 (last updated February 21, 2025)
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'.
Attacker Value
Unknown

CVE-2019-1332

Disclosure Date: December 10, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.