PT-2020-13399 · Contentful · Contentful
Tr3Jer
·
Published
2020-05-21
·
Updated
2021-06-18
·
CVE-2020-13258
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Contentful versions prior to 2020-05-21
Description
The issue allows reflected XSS, as demonstrated by the
api parameter to the /the-example-app.py endpoint.Recommendations
For versions prior to 2020-05-21, update to a version released after 2020-05-21 to resolve the issue. As a temporary workaround, consider restricting access to the
api parameter in the affected endpoint until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contentful