6.1
CVSSv3

CVE-2019-12453

Published: 19/07/2019 Updated: 05/08/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In MicroStrategy Web prior to 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microstrategy microstrategy web

Github Repositories

Authenticated XSS in Microstrategy Web - Versions prior to 10.1 patch 10

CVE-2019-12453 CVE-2019-12453 Stored XSS in MicroStrategy Web prior to 101 patch 10 Author: undefinedmode githubcom/undefinedmode/CVE-2019-12453 In MicroStrategy Web prior to version 101 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation The FLTB parameter is used throughout the application

Stored XSS in MicroStrategy Web prior to 10.4.6

CVE-2019-12475 Stored XSS in MicroStrategy Web prior to 1046 Author: undefinedmode githubcom/undefinedmode/CVE-2019-12453 Stored XSS in metric and it is triggered when opening the Visual Threshold editor Reported to vendor in 2017 and fixed quickly in version 1046