CVE-2020-22986: Microstrategy Web SDK
Medium severity, CVSS 6.1. EPSS: 1.6% chance of exploitation in the next 30 days.
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task.
Affected products
- Microstrategy Microstrategy Web SDK: up to and including 10.11
Published 2022-05-12. Last modified 2026-07-09.