Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation of a new dashboard. In order to exploit this vulnerability, a user needs to get access to a shared dashboard or have the ability to create a dashboard on the application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-04-02T14:58:59
Updated: 2024-08-04T11:28:14.055Z
Reserved: 2020-04-01T00:00:00
Link: CVE-2020-11454
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-02T15:15:17.653
Modified: 2024-11-21T04:57:57.240
Link: CVE-2020-11454
Redhat
No data.