VYPR
Medium severity4.3NVD Advisory· Published Nov 1, 2018· Updated Jun 17, 2026

CVE-2018-18777

CVE-2018-18777

Description

Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application. NOTE: this is a deprecated product.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • MicroStrategy/Web2 versions
    cpe:2.3:a:microstrategy:microstrategy_web:7:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microstrategy:microstrategy_web:7:*:*:*:*:*:*:*
    • (no CPE)range: 7

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.