Security for everyone

CVE-2020-35774 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in twitter/twitter-server affects v. before 20.12.0.

SCAN NOW

Short Info


Level

Medium

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 sec

Scan only one

Url

Toolbox

-

Twitter is one of the world's leading social media platforms that enables communication between people, businesses, and advertisers. To support its infrastructure, Twitter Server is an open-source project used by Twitter, as well as developers across the globe, for building scalable and fault-resistant services. With its easy-to-use and flexible architecture, Twitter Server provides a wide range of features such as load balancing, request routing, and service discovery.

The vulnerability code CVE-2020-35774 was detected in the HistogramQueryHandler.scala module of Twitter Server, which is responsible for handling histogram queries. The vulnerability occurs when an attacker is able to inject cross-site scripting (XSS) code into the histograms endpoint. In some configurations, the endpoint does not sanitize user input, leading to the execution of malicious scripts within the user's browser.

Exploiting this vulnerability can lead to a range of attacks, such as the theft of confidential information, corporate espionage, identity theft, and the spreading of malware. Since XSS attacks allow attackers to execute arbitrary code on the victim's browser, the attacker can use this access to redirect the user to malicious websites, steal login credentials, or install malware on the user's computer.

With the pro version of the SecurityforEveryone.com platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform provides detailed reports, alerts, and expert analysis to help users identify weaknesses and prioritize their security efforts. By using SecurityforEveryone.com, users can stay ahead of the curve and protect themselves against emerging threats.

 

REFERENCES

cyber security services for everyone one. Free security tools, continuous vulnerability scanning and many more.
Try it yourself,
control security posture