CVE-2020-19007: XSS
Published Aug 26, 2020
·Updated
Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.
Affected Software
1 affected component
Halo Halo=1.2.0
Event History
Aug 26, 2020
CVE Published
via MITRE·01:21 PM
Data Sourced
via MITRE·01:21 PM
Description
Frequently Asked Questions
1
What is CVE-2020-19007?
CVE-2020-19007 is a vulnerability in Halo blog 1.2.0 that allows users to submit comments on blog posts via /api/content/posts/comments, leading to the execution of attacker-supplied JavaScript code in the victim user's browser.
2
How severe is CVE-2020-19007?
CVE-2020-19007 has a severity level of 5.4, classified as medium severity.
3
How can I mitigate CVE-2020-19007?
To mitigate CVE-2020-19007, consider updating to a patched version of Halo blog that addresses the vulnerability.