VYPR

Microstrategy

by MicroStrategy

CVEs (2)

  • CVE-2018-18696HigDec 28, 2018
    risk 0.57cvss 8.8epss 0.01

    main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?lang…

  • CVE-2020-24815MedNov 24, 2020
    risk 0.42cvss 6.5epss 0.02

    A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the local system via HTML containers embedded…