[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Microsoft SQL Server Reporting Services XSS Vulnerability - CVE-2019-1332

ID: oval:org.secpod.oval:def:61265Date: (C)2020-01-25   (M)2023-08-24
Class: VULNERABILITYFamily: windows




A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server. An attacker who successfully exploited the vulnerability could run scripts in the context of the targeted user. The attacks could allow the attacker to read content that the attacker is not authorized to read, execute malicious code, and use the victim's identity to take actions on the site on behalf of the user, such as change permissions and delete content. To exploit the vulnerability, an attacker would need to convince an authenticated user to click a specially-crafted link to an affected SSRS server.

Platform:
Microsoft Windows 10
Microsoft Windows 7
Microsoft Windows 8.1
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows 11
Microsoft Windows Server
Microsoft Windows Server 2022
Product:
Microsoft SQL Server 2016
Microsoft SQL Server 2017 Reporting Services
Microsoft SQL Server 2019 Reporting Services
Reference:
CVE-2019-1332
CVE    1
CVE-2019-1332
CPE    2
cpe:/a:microsoft:sql_server:2016
cpe:/a:microsoft:sql_server:2016:sp2

© SecPod Technologies