CVE-2024-43793
Halo is an open source website building tool. A security

Publication date: 2024-09-11

Last updated on: 2024-09-16

Assigner: [email protected]

Description
Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the users browser through specific HTML and JavaScript code, potentially leading to a Cross-Site Scripting XSS attack. This vulnerability is fixed in 2.19.0.
CVSS Scores
Affected Vendors & Products
Vendor Product Version
halo halo *
Exploitability
CWE ID Description
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
Meta Information
Date published:
2024-09-11
Date last modified:
2024-09-16
Date generated:
2025-01-15
NVD report: