VYPR

Web SDK

by MicroStrategy

CVEs (5)

  • CVE-2020-22983HigMay 13, 2022
    risk 0.53cvss 8.1epss 0.02

    A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

  • CVE-2020-22987MedMay 12, 2022
    risk 0.40cvss 6.1epss 0.01

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.

  • CVE-2020-22986MedMay 12, 2022
    risk 0.40cvss 6.1epss 0.02

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task.

  • CVE-2020-22985MedMay 12, 2022
    risk 0.40cvss 6.1epss 0.02

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

  • CVE-2020-22984MedMay 12, 2022
    risk 0.40cvss 6.1epss 0.02

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task.