Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation of a new dashboard. In order to exploit this vulnerability, a user needs to get access to a shared dashboard or have the ability to create a dashboard on the application.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-04-02T14:58:59

Updated: 2024-08-04T11:28:14.055Z

Reserved: 2020-04-01T00:00:00

Link: CVE-2020-11454

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-02T15:15:17.653

Modified: 2020-04-03T19:15:13.077

Link: CVE-2020-11454

cve-icon Redhat

No data.