CVE-2020-35774 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in twitter/twitter-server affects v. before 20.12.0.


CVE-2020-35774 Scanner Detail

Twitter is one of the world's leading social media platforms that enables communication between people, businesses, and advertisers. To support its infrastructure, Twitter Server is an open-source project used by Twitter, as well as developers across the globe, for building scalable and fault-resistant services. With its easy-to-use and flexible architecture, Twitter Server provides a wide range of features such as load balancing, request routing, and service discovery.

The vulnerability code CVE-2020-35774 was detected in the HistogramQueryHandler.scala module of Twitter Server, which is responsible for handling histogram queries. The vulnerability occurs when an attacker is able to inject cross-site scripting (XSS) code into the histograms endpoint. In some configurations, the endpoint does not sanitize user input, leading to the execution of malicious scripts within the user's browser.

Exploiting this vulnerability can lead to a range of attacks, such as the theft of confidential information, corporate espionage, identity theft, and the spreading of malware. Since XSS attacks allow attackers to execute arbitrary code on the victim's browser, the attacker can use this access to redirect the user to malicious websites, steal login credentials, or install malware on the user's computer.

