7.2
CVSSv3

CVE-2020-11451

Published: 02/04/2020 Updated: 09/06/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files with arbitrary extensions and data. (This is also exploitable via SSRF). Note: The ability to upload visualization plugins requires administrator privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microstrategy microstrategy web

Exploits

MicroStrategy Intelligence Server and Web version 104 suffers from remote code execution, cross site scripting, server-side request forgery, and information disclosure vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> MicroStrategy Intelligence Server and Web 104 - multiple vulnerabilities <!--X-Subject-Header-End--> <!--X-Head-of-Me ...