CVE-2020-37044

OpenCTI 3.3.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the /graphql endpoint. An attacker can inject arbitrary JavaScript code by sending a crafted GET request with a malicious payload in the query string, leading to execution of JavaScript in the victim's browser. For example, a request to /graphql?'"--></style></scRipt><scRipt>alert('Raif_Berkay')</scRipt> will trigger an alert. This vulnerability was discovered by Raif Berkay Dincel and confirmed on Linux Mint and Windows 10.
Configurations

Configuration 1 (hide)

cpe:2.3:a:citeum:opencti:3.3.1:*:*:*:*:*:*:*

History

17 Jun 2026, 03:16

Type Values Removed Values Added
Summary
  • (es) OpenCTI 3.3.1 es vulnerable a un ataque de tipo cross-site scripting (XSS) reflejado a través del punto final /graphql. Un atacante puede inyectar código JavaScript arbitrario enviando una solicitud GET diseñada con una carga maliciosa en la cadena de consulta, lo que provoca la ejecución de JavaScript en el navegador de la víctima. Por ejemplo, una solicitud a /graphql?“"--&gt; activará una alerta. Esta vulnerabilidad fue descubierta por Raif Berkay Dincel y confirmada en Linux Mint y Windows 10.

13 Feb 2026, 17:55

Type Values Removed Values Added
References () https://github.com/OpenCTI-Platform/opencti - () https://github.com/OpenCTI-Platform/opencti - Product
References () https://www.exploit-db.com/exploits/48595 - () https://www.exploit-db.com/exploits/48595 - Exploit, Third Party Advisory, VDB Entry
References () https://www.opencti.io/ - () https://www.opencti.io/ - Product
References () https://www.vulncheck.com/advisories/opencti-cross-site-scripting - () https://www.vulncheck.com/advisories/opencti-cross-site-scripting - Broken Link
CPE cpe:2.3:a:citeum:opencti:3.3.1:*:*:*:*:*:*:*
First Time Citeum
Citeum opencti

30 Jan 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-30 23:16

Updated : 2026-06-17 03:16


NVD link : CVE-2020-37044

Mitre link : CVE-2020-37044

CVE.ORG link : CVE-2020-37044


JSON object : View

Products Affected

citeum

  • opencti
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')