CVE-2020-18982: XSS
Published Jul 12, 2021
·Updated
Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl.
Affected Software
1 affected component
Halo Halo=0.4.3
Event History
Jul 12, 2021
CVE Published
via MITRE·04:08 PM
Data Sourced
via MITRE·04:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-18982?
CVE-2020-18982 is classified as a medium severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2020-18982?
To fix CVE-2020-18982, update your Halo installation to version 0.4.4 or later.
3
What software is affected by CVE-2020-18982?
CVE-2020-18982 affects Halo version 0.4.3.
4
What is Cross Site Scripting in relation to CVE-2020-18982?
CVE-2020-18982 involves a Cross Site Scripting (XSS) flaw that allows attackers to inject malicious scripts through the CommentAuthorUrl field.
5
Can CVE-2020-18982 be exploited remotely?
Yes, CVE-2020-18982 can be exploited remotely, allowing attackers to potentially execute scripts in the context of user sessions.