Medium severity6.1NVD Advisory· Published May 12, 2022· Updated Jul 9, 2026
CVE-2020-22987
CVE-2020-22987
Description
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.
Affected products
3- MicroStrategy/Web SDKdescription
<=10.11+ 1 more
- (no CPE)range: <=10.11
- cpe:2.3:a:microstrategy:microstrategy_web_sdk:*:*:*:*:*:*:*:*range: <=10.11
Patches
Vulnerability mechanics
References
4- www.microstrategy.com/us/report-a-security-vulnerabilitynvdVendor Advisory
- www.yourcompany.com:8080/MicroStrategy/servlet/taskProcnvdBroken Link
- medium.com/%40win3zz/simple-story-of-some-complicated-xss-on-facebook-8a9c0d80969dnvd
- medium.com/@win3zz/simple-story-of-some-complicated-xss-on-facebook-8a9c0d80969dnvd
News mentions
0No linked articles in our index yet.