Skip to content

Authenticated XSS in Microstrategy Web - Versions prior to 10.1 patch 10

Notifications You must be signed in to change notification settings

undefinedmode/CVE-2019-12453

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 

Repository files navigation

CVE-2019-12453

CVE-2019-12453 Stored XSS in MicroStrategy Web prior to 10.1 patch 10

Author: undefinedmode https://github.com/undefinedmode/CVE-2019-12453

In MicroStrategy Web prior to version 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation. The FLTB parameter is used throughout the application.

About

Authenticated XSS in Microstrategy Web - Versions prior to 10.1 patch 10

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published