haxpunk1337/MicroStrategy-Enterprise-Manager-2022

haxpunk1337/MicroStrategy-Enterprise-Manager-2022

Releases0
Stars1

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=_any_password_&ConnMode=1&3054=Login substring for directory traversal.