CVE-2020-36324: XSS
Published Apr 21, 2021
·Updated
Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json content type.
Affected Software
1 affected component
Wikimedia analytics-quarry-web<2020-12-15
Remediation
Event History
Apr 21, 2021
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-36324?
CVE-2020-36324 is considered a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2020-36324?
To fix CVE-2020-36324, update to Wikimedia Analytics-quarry-web version 2020-12-15 or later.
3
What version of Wikimedia Analytics-quarry-web is affected by CVE-2020-36324?
Versions of Wikimedia Analytics-quarry-web prior to 2020-12-15 are affected by CVE-2020-36324.
4
Can CVE-2020-36324 lead to data theft?
Yes, CVE-2020-36324 can potentially allow attackers to steal user data through reflected XSS.
5
Is CVE-2020-36324 a common vulnerability?
While not extremely common, reflected XSS vulnerabilities like CVE-2020-36324 can be prevalent in web applications that do not properly handle user input.