
CVE-2020-37044 OpenCTI 3.3.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the /graphql endpoint. An attacker can inject arbitrary JavaScript code by sending a … https://www.cve.org/CVERecord?id=CVE-2020-37044
Post summary
CVE‑2020‑37044 in OpenCTI 3.3.1 permits reflected XSS through the /graphql endpoint, allowing attackers to inject arbitrary JavaScript code.
