CVE-2020-36324: Wikimedia Analytics-Quarry-Web
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json content type.
Affected products
- Wikimedia Analytics-Quarry-Web: before 2020-12-15 (fixed in 2020-12-15)
Published 2021-04-21. Last modified 2026-06-17.