.. / CVE-2020-35774

Exploit for twitter-server Cross-Site Scripting (CVE-2020-35774)

Description:

twitter-server before 20.12.0 is vulnerable to cross-site scripting in some configurations. The vulnerability exists in the administration panel of twitter-server in the histograms component via server/handler/HistogramQueryHandler.scala.

Nuclei Template

View the template here CVE-2020-35774.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-35774.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://github.com/twitter/twitter-server/commit/e0aeb87e89a6e6c711214ee2de0dd9f6e5f9cb6c
https://nvd.nist.gov/vuln/detail/CVE-2020-35774
https://advisory.checkmarx.net/advisory/CX-2020-4287
https://github.com/twitter/twitter-server/compare/twitter-server-20.10.0...twitter-server-20.12.0