Medium severity4.3NVD Advisory· Published Nov 1, 2018· Updated Jun 17, 2026
CVE-2018-18777
CVE-2018-18777
Description
Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application. NOTE: this is a deprecated product.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:microstrategy:microstrategy_web:7:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microstrategy:microstrategy_web:7:*:*:*:*:*:*:*
- (no CPE)range: 7
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/150059/Microstrategy-Web-7-Cross-Site-Scripting-Traversal.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/45755/nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.