CVE-2020-22985: Microstrategy Web SDK

Medium severity, CVSS 6.1. EPSS: 1.7% chance of exploitation in the next 30 days.

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

Affected products

Published 2022-05-12. Last modified 2026-07-09.