cve/2020/CVE-2020-22985.md
2024-05-25 21:48:12 +02:00

715 B

CVE-2020-22985

Description

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

POC

Reference

Github

No PoCs found on GitHub currently.