CVE-2020-22985
- EPSS 1.87%
- Veröffentlicht 12.05.2022 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:13:29
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.
CVE-2020-22986
- EPSS 1.91%
- Veröffentlicht 12.05.2022 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:13:29
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task.
CVE-2020-22987
- EPSS 1.87%
- Veröffentlicht 12.05.2022 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:13:29
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.
CVE-2020-22984
- EPSS 1.87%
- Veröffentlicht 12.05.2022 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:13:29
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task.