diff --git a/cves/2020/CVE-2020-13258.yaml b/cves/2020/CVE-2020-13258.yaml new file mode 100644 index 0000000000..f157760798 --- /dev/null +++ b/cves/2020/CVE-2020-13258.yaml @@ -0,0 +1,20 @@ +id: CVE-2020-13258 + +info: + name: Contentful reflected XSS + author: pikpikcu + severity: medium + description: Contentful through 2020-05-21 for Python allows reflected XSS. + reference: https://nvd.nist.gov/vuln/detail/CVE-2020-13258 + tags: cve,cve2020,contentful,xss +requests: + - method: GET + path: + - '{{BaseURL}}/?cda'"&locale=locale=de-DE' + + matchers-condition: and + matchers: + - type: word + words: + - "" + condition: and