CVE-2020-22985

Publication date

2022-05-12 19:58:23

Family

mitre

State

PUBLISHED

Description

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.