VYPR
Medium severity6.1NVD Advisory· Published Apr 21, 2021· Updated Jun 17, 2026

CVE-2020-36324

CVE-2020-36324

Description

Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json content type.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:wikimedia:analytics-quarry-web:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:wikimedia:analytics-quarry-web:*:*:*:*:*:*:*:*range: <2020-12-15
    • (no CPE)range: <2020-12-15
  • Wikimedia/Quarry analytics-quarry-webdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.