
CVE-2024-43612 – Power BI Report Server Spoofing Vulnerability
https://notcve.org/view.php?id=CVE-2024-43612
08 Oct 2024 — Power BI Report Server Spoofing Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43612 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-43481 – Power BI Report Server Spoofing Vulnerability
https://notcve.org/view.php?id=CVE-2024-43481
08 Oct 2024 — Power BI Report Server Spoofing Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43481 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-21806 – Power BI Report Server Spoofing Vulnerability
https://notcve.org/view.php?id=CVE-2023-21806
14 Feb 2023 — Power BI Report Server Spoofing Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21806 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-41372 – Power BI Report Server Spoofing Vulnerability
https://notcve.org/view.php?id=CVE-2021-41372
10 Nov 2021 — A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities together, an attacker is able to upload malicious Power BI templates files to the server using the victim's session and run scripts in the security context of the user and perform privilege escalation in case the victim has admin privileges ... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41372 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2021-31984 – Power BI Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-31984
14 Jul 2021 — Power BI Remote Code Execution Vulnerability Una vulnerabilidad de Ejecución de Código Remota en Power BI • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31984 •

CVE-2021-26859 – Microsoft Power BI Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-26859
11 Mar 2021 — Microsoft Power BI Information Disclosure Vulnerability Una Vulnerabilidad de Divulgación de Información de Microsoft Power BI • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26859 •

CVE-2020-1173
https://notcve.org/view.php?id=CVE-2020-1173
21 May 2020 — A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'. Se presenta una vulnerabilidad de suplantación de identidad en Microsoft Power BI Report Server en la manera en que comprueba el content-type de archivos adjuntos cargados, también se conoce como "Microsoft Power BI Report Server Spoofing Vulnerability". • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1173 • CWE-20: Improper Input Validation •

CVE-2019-1332
https://notcve.org/view.php?id=CVE-2019-1332
10 Dec 2019 — A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'. Hay una vulnerabilidad de tipo cross-site scripting (XSS) cuando Microsoft SQL Server Reporting Services (SSRS) no sanea apropiadamente una petición web especialmente diseñada para un servidor SSRS afectado, también se conoce como "Microsoft SQL Server Repor... • https://github.com/mbadanoiu/CVE-2019-1332 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •