vendor:
Microstrategy Web
by:
Rafael Pedrero
6.1
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Microstrategy Web
Affected Version From: 7
Affected Version To: 7
Patch Exists: YES
Related CWE: CVE-2018-18775
CPE: a:microstrategy:microstrategy_web:7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Unix
2018
Cross Site Scripting in Microstrategy Web version 7
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter.
Mitigation:
Update to last version this product and patch from https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet#XSS_Prevention_Rules