383
VMScore

CVE-2019-12475

Published: 17/07/2019 Updated: 05/08/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In MicroStrategy Web prior to 10.4.6, there is stored XSS in metric due to insufficient input validation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microstrategy microstrategy web

Github Repositories

Stored XSS in MicroStrategy Web prior to 10.4.6

CVE-2019-12475 Stored XSS in MicroStrategy Web prior to 1046 Author: undefinedmode githubcom/undefinedmode/CVE-2019-12453 Stored XSS in metric and it is triggered when opening the Visual Threshold editor Reported to vendor in 2017 and fixed quickly in version 1046