CVE-2020-35774

MEDIUM6.1EPSS 81.9%

TwitterServer Cross-site Scripting via /histograms endpoint

Published: 2/9/2022Modified: 11/8/2023
Also known as:GHSA-3mqv-8gxg-pfm4

Description

server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (5)