CVE-2020-37044 - CVE House
Back to Database
Status published Medium CVE-2020-37044

OpenCTI 3.3.1 - Cross Site Scripting

Vulnerability Description

OpenCTI 3.3.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the /graphql endpoint. An attacker can inject arbitrary JavaScript code by sending a crafted GET request with a malicious payload in the query string, leading to execution of JavaScript in the victim's browser. For example, a request to /graphql?'"--></style></scRipt><scRipt>alert('Raif_Berkay')</scRipt> will trigger an alert. This vulnerability was discovered by Raif Berkay Dincel and confirmed on Linux Mint and Windows 10.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37044

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Raif Berkay Dincel

Affected Vendor

Affected Software

OpenCTI
Vulnerable Versions:
3.3.1

Timeline

Official Publish: January 30th, 2026
Last Modified: March 5th, 2026
Added to House: July 21st, 2026

CVSS Vectors

Weaknesses (CWE)