CVE-2018-18696
Last modified
CVE-2018-18696 is a vulnerability of currently unknown severity. main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?language=en_US) and disagrees that this issue is a vulnerability. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?language=en_US) and disagrees that this issue is a vulnerability. They also claim that MicroStrategy was never properly informed of this issue via normal support channels or their vulnerability reporting page on their website, so they were unable to evaluate the report or explain how this is something their customers view as a feature and not a security vulnerability
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microstrategy | Microstrategy | <= 10.4.0026.0049 |
References
- https://raw.githubusercontent.com/Siros96/MicroStrategy_CSRF/master/PoCExploit, Third Party Advisory
- https://seclists.org/bugtraq/2018/Dec/3Exploit, Mailing List, Third Party Advisory
- https://raw.githubusercontent.com/Siros96/MicroStrategy_CSRF/master/PoCExploit, Third Party Advisory
- https://seclists.org/bugtraq/2018/Dec/3Exploit, Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-18696?
How severe is CVE-2018-18696?
How do I fix CVE-2018-18696?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-18688The Portable Document Format (PDF) specification does not pr…5.3
- CVE-2018-18689The Portable Document Format (PDF) specification does not pr…5.3
- CVE-2018-18690In the Linux kernel before 4.17, a local attacker able to se…
- CVE-2018-18692A reflected Cross-Site scripting (XSS) vulnerability in SEMC…
- CVE-2018-18694admin/index.php?id=filesmanager in Monstra CMS 3.0.4 allows …
- CVE-2018-18695M2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow w…
- CVE-2018-18698An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/…
- CVE-2018-18699An issue was discovered in GoPro gpmf-parser 1.2.1. There is…
- CVE-2018-18700An issue was discovered in cp-demangle.c in GNU libiberty, a…
- CVE-2018-18701An issue was discovered in cp-demangle.c in GNU libiberty, a…
- CVE-2018-18702spider.admincp.php in iCMS v7.0.11 allows SQL injection via …
- CVE-2018-18703PhpTpoint Mailing Server Using File Handling 1.0 suffers fro…
Are you affected by CVE-2018-18696?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
