cve/2022/CVE-2022-29596.md
2024-06-18 02:51:15 +02:00

740 B

CVE-2022-29596

Description

MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=any_password&ConnMode=1&3054=Login substring for directory traversal.

POC

Reference

Github

No PoCs found on GitHub currently.