4.3
CVSSv2

CVE-2019-1332

Published: 10/12/2019 Updated: 01/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft power bi report server -

microsoft sql server 2017 reporting services -

microsoft sql server 2019 reporting services -

Github Repositories

CVE-2019-1332: Reflected Cross-Site Scripting in Microsoft SQL Server Reporting Services

CVE-2019-1332: Reflected Cross-Site Scripting in Microsoft SQL Server Reporting Services A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server An attacker who successfully exploited the vulnerability could run scripts in the context of the targe

Recent Articles

Microsoft Patch Tuesday – December 2019
Symantec Threat Intelligence Blog • Preethi Koroth • 11 Dec 2024

This month the vendor has patched 36 vulnerabilities, 7 of which are rated Critical.

Posted: 11 Dec, 201911 Min ReadThreat Intelligence SubscribeMicrosoft Patch Tuesday – December 2019This month the vendor has patched 36 vulnerabilities, 7 of which are rated Critical.This month the vendor has patched 36 vulnerabilities, 7 of which are rated Critical. As always, customers are advised to follow these security best practices: Install vendor patches as soon as they are available. Run all software with the least privileges required w...