CVE-2020-22983

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
13/05/2022
Last modified:
07/11/2023

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microstrategy:microstrategy_web:*:*:*:*:*:*:*:* 11.1 (including)