Description
Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-10914 | Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser. |
References
| Link | Providers |
|---|---|
| https://github.com/halo-dev/halo/issues/547 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T14:08:30.583Z
Reserved: 2020-08-13T00:00:00.000Z
Link: CVE-2020-19007
No data.
Status : Modified
Published: 2020-08-26T14:15:10.637
Modified: 2024-11-21T05:08:54.960
Link: CVE-2020-19007
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD