GHSA-2cj8-f8jw-33qqMediumCVSS 6.1

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows...

Published
May 13, 2022
Last Modified
July 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

🔗 References (7)