CVE-2019-1332 is a cross-site scripting (XSS) vulnerability in Microsoft SQL Server Reporting Services (SSRS) that affects Power BI Report Server, SQL Server 2017 Reporting Services, and SQL Server 2019 Reporting Services. This medium-severity vulnerability (CVSS 6.1) allows an unauthenticated attacker to inject malicious scripts via a specially crafted web request, potentially leading to information disclosure and integrity compromise if a user interacts with the malicious content. There is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is not available. While there has been some community discussion and media coverage, it is not currently on CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:power_bi_report_server:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017_reporting_services:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2019_reporting_services:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.