4.3
CVSSv3

CVE-2020-11452

Published: 02/04/2020 Updated: 03/04/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases. By providing an external URL under attacker control, it's possible to send requests to external resources (aka SSRF) or leak files from the local system using the file:// stream wrapper.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microstrategy microstrategy web

Exploits

MicroStrategy Intelligence Server and Web version 104 suffers from remote code execution, cross site scripting, server-side request forgery, and information disclosure vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> MicroStrategy Intelligence Server and Web 104 - multiple vulnerabilities <!--X-Subject-Header-End--> <!--X-Head-of-Me ...