8 results (0.011 seconds)

CVSS: 6.9EPSS: 0%CPEs: 1EXPL: 0

08 Oct 2024 — Power BI Report Server Spoofing Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43612 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 0

08 Oct 2024 — Power BI Report Server Spoofing Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43481 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.2EPSS: 0%CPEs: 1EXPL: 0

14 Feb 2023 — Power BI Report Server Spoofing Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21806 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.6EPSS: 0%CPEs: 1EXPL: 0

10 Nov 2021 — A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities together, an attacker is able to upload malicious Power BI templates files to the server using the victim's session and run scripts in the security context of the user and perform privilege escalation in case the victim has admin privileges ... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41372 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 8.8EPSS: 1%CPEs: 1EXPL: 0

14 Jul 2021 — Power BI Remote Code Execution Vulnerability Una vulnerabilidad de Ejecución de Código Remota en Power BI • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31984 •

CVSS: 7.7EPSS: 13%CPEs: 2EXPL: 0

11 Mar 2021 — Microsoft Power BI Information Disclosure Vulnerability Una Vulnerabilidad de Divulgación de Información de Microsoft Power BI • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26859 •

CVSS: 6.8EPSS: 1%CPEs: 1EXPL: 0

21 May 2020 — A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'. Se presenta una vulnerabilidad de suplantación de identidad en Microsoft Power BI Report Server en la manera en que comprueba el content-type de archivos adjuntos cargados, también se conoce como "Microsoft Power BI Report Server Spoofing Vulnerability". • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1173 • CWE-20: Improper Input Validation •

CVSS: 6.1EPSS: 1%CPEs: 3EXPL: 2

10 Dec 2019 — A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'. Hay una vulnerabilidad de tipo cross-site scripting (XSS) cuando Microsoft SQL Server Reporting Services (SSRS) no sanea apropiadamente una petición web especialmente diseñada para un servidor SSRS afectado, también se conoce como "Microsoft SQL Server Repor... • https://github.com/mbadanoiu/CVE-2019-1332 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •