Описание
A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.
Ссылки
- Vendor Advisory
- Broken Link
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Broken Link
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.1 (включая)
cpe:2.3:a:microstrategy:microstrategy_web:*:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.0195
Низкий
8.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 8.1
github
около 3 лет назад
A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.
EPSS
Процентиль: 83%
0.0195
Низкий
8.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-918