← Back to CVE List

CVE-2020-11452

Published: 2020-04-02T16:15Z
Last Modified: 2024-11-21T04:57Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases. By providing an external URL under attacker control, it's possible to send requests to external resources (aka SSRF) or leak files from the local system using the file:// stream wrapper. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt