CVE-2021-41372 is a critical Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability affecting Microsoft Power BI Report Server. It allows an unauthenticated attacker to upload malicious Power BI template files containing HTML, which, when accessed by a victim, can lead to script execution in the user's security context and potential privilege escalation if the victim has administrative rights. With a CVSS score of 9.6 (Critical), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.0.1107.165CPE matchmatch criteria | cpe:2.3:a:microsoft:power_bi_report_server:15.0.1107.165:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.