CVE-2024-43793
Halo is an open source website building tool. A security
Description
Description
Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the users browser through specific HTML and JavaScript code, potentially leading to a Cross-Site Scripting XSS attack. This vulnerability is fixed in 2.19.0.
CVSS Scores
Affected Vendors & Products
Vendor | Product | Version |
---|---|---|
halo | halo | * |
Helpful Resources
Exploitability
CWE ID | Description |
---|---|
CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
Meta Information
Date published:
2024-09-11
Date last modified:
2024-09-16
Date generated:
2025-01-15
NVD report: