CVE-2020-18979: XSS
Published Jul 12, 2021
·Updated
Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via the X-forwarded-for Header parameter.
Affected Software
1 affected component
Halo Halo=0.4.3
Event History
Jul 12, 2021
CVE Published
via MITRE·02:43 PM
Data Sourced
via MITRE·02:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-18979?
CVE-2020-18979 is classified as a medium-severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2020-18979?
To fix CVE-2020-18979, ensure that input from the X-forwarded-for Header parameter is properly sanitized and validated.
3
Which versions of Halo are affected by CVE-2020-18979?
CVE-2020-18979 specifically affects Halo version 0.4.3.
4
What type of attack can be executed using CVE-2020-18979?
CVE-2020-18979 allows attackers to execute Cross-Site Scripting (XSS) attacks, potentially leading to data theft or session hijacking.
5
Is CVE-2020-18979 a publicly known vulnerability?
Yes, CVE-2020-18979 is a publicly disclosed vulnerability identified in Halo software.