Record summary

CVE-2020-35774 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

com.twitter:twitter-server_2.12

Browse Maven / com.twitter:twitter-server_2.12
GitHub AdvisoryBefore 20.12.0 · Fixed in 20.12.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMtwitter-server Cross-Site ScriptingCVSS 5.4

twitter-server before 20.12.0 is vulnerable to cross-site scripting in some configurations. The vulnerability exists in the administration panel of twitter-server in the histograms component via server/handler/HistogramQueryHandler.scala.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim's browser, potentially leading to session hijacking, data theft, or defacement.

Remediation

Apply the latest security patches or updates provided by Twitter to mitigate the XSS vulnerability.

WeaknessesCWE-79
Authorspikpikcu
Template tagscve2020cvexsstwitter-servertwittervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:twitter:twitter-server:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5