Vulnerability CVE-2020-22985


Published: 2022-05-12

Description:
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

 References:
https://www.microstrategy.com/us/report-a-security-vulnerability
https://medium.com/@win3zz/simple-story-of-some-complicated-xss-on-facebook-8a9c0d80969d
http://www.yourcompany.com:8080/MicroStrategy/servlet/taskProc
http://microstrategy.com

Copyright 2026, cxsecurity.com

 

Back to Top