CVE-2019-1332: Microsoft Power BI Report Server
Medium severity, CVSS 6.1. EPSS: 10.9% chance of exploitation in the next 30 days.
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.
Affected products
- Microsoft Power BI Report Server: affected versions not specified
- Microsoft SQL Server 2017 Reporting Services: affected versions not specified
- Microsoft SQL Server 2019 Reporting Services: affected versions not specified
Published 2019-12-10. Last modified 2026-06-17.