Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the user's browser through specific HTML and JavaScript code, potentially leading to a Cross-Site Scripting (XSS) attack. This vulnerability is fixed in 2.19.0.
History

Mon, 16 Sep 2024 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:halo:halo:*:*:*:*:*:*:*:*

Wed, 11 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Halo
Halo halo
CPEs cpe:2.3:a:halo:halo:-:*:*:*:*:*:*:*
Vendors & Products Halo
Halo halo
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Sep 2024 14:45:00 +0000

Type Values Removed Values Added
Description Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the user's browser through specific HTML and JavaScript code, potentially leading to a Cross-Site Scripting (XSS) attack. This vulnerability is fixed in 2.19.0.
Title Halo's editor has a stored XSS vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-09-11T14:37:57.666Z

Updated: 2024-09-11T15:01:32.493Z

Reserved: 2024-08-16T14:20:37.324Z

Link: CVE-2024-43793

cve-icon Vulnrichment

Updated: 2024-09-11T15:01:25.959Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-11T15:15:17.017

Modified: 2024-09-16T16:28:45.233

Link: CVE-2024-43793

cve-icon Redhat

No data.