Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-1332. PoCs published by mbadanoiu.
AI-analyzed exploit summary The repository describes a reflected XSS vulnerability in Microsoft SQL Server Reporting Services but lacks actual exploit code, instead pointing to an external PDF for details. This is indicative of a social engineering lure rather than a legitimate PoC.
Description
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.
Exploits (1)
The repository describes a reflected XSS vulnerability in Microsoft SQL Server Reporting Services but lacks actual exploit code, instead pointing to an external PDF for details. This is indicative of a social engineering lure rather than a legitimate PoC.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N