Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.py.
References
Link | Resource |
---|---|
https://github.com/contentful/the-example-app.py/issues/44 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2020-05-21 10:15
Updated : 2020-05-21 11:45
NVD link : CVE-2020-13258
Mitre link : CVE-2020-13258
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
contentful
- python_example