Medium severity6.1NVD Advisory· Published Apr 21, 2021· Updated Jun 17, 2026
CVE-2020-36324
CVE-2020-36324
Description
Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json content type.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:wikimedia:analytics-quarry-web:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:wikimedia:analytics-quarry-web:*:*:*:*:*:*:*:*range: <2020-12-15
- (no CPE)range: <2020-12-15
- Wikimedia/Quarry analytics-quarry-webdescription
Patches
Vulnerability mechanics
References
2- github.com/wikimedia/analytics-quarry-web/commit/4b7e1d6a3a52ec6cf826a971135a38b0f74785d2nvdPatchThird Party Advisory
- quarry.wmflabs.orgnvdProductThird Party Advisory
News mentions
0No linked articles in our index yet.