main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?language=en_US) and disagrees that this issue is a vulnerability. They also claim that MicroStrategy was never properly informed of this issue via normal support channels or their vulnerability reporting page on their website, so they were unable to evaluate the report or explain how this is something their customers view as a feature and not a security vulnerability
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-12-28T17:00:00
Updated: 2024-08-05T11:16:00.382Z
Reserved: 2018-10-26T00:00:00
Link: CVE-2018-18696
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-12-28T17:29:00.683
Modified: 2024-11-21T03:56:23.387
Link: CVE-2018-18696
Redhat
No data.