Skip to main content
will trigger an alert. This vulnerability was discovered by Raif Berkay Dincel and confirmed on Linux Mint and Windows 10.","url":"https://cvebuzz.com/cve/CVE-2020-37044","datePublished":"2026-01-30T23:16:10.257000Z","dateModified":"2026-06-17T03:16:50.013000Z","isPartOf":{"@type":"WebSite","name":"cvebuzz","url":"https://cvebuzz.com"}}

CVE detail

CVE-2020-37044

OpenCTI 3.3.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the /graphql endpoint. An attacker can inject arbitrary JavaScript code by sending a crafted GET request with a malicious payload in the query string, leading to execution of JavaScript in the victim's browser. For example, a request to /graphql?'"--></style></scRipt><scRipt>alert('Raif_Berkay')</scRipt> will trigger an alert. This vulnerability was discovered by Raif Berkay Dincel and confirmed on Linux Mint and Windows 10.

CVSS 5.1 · Medium