CVE-2020-21345: XSS
Published May 20, 2021
·Updated
Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a remote malicious user execute arbitrary code.
Affected Software
1 affected component
Halo Halo=1.1.3
Event History
May 20, 2021
CVE Published
via MITRE·04:51 PM
Data Sourced
via MITRE·04:51 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-21345?
CVE-2020-21345 is considered a high severity vulnerability due to its potential for arbitrary code execution via XSS.
2
How do I fix CVE-2020-21345?
To fix CVE-2020-21345, upgrade Halo to version 1.1.4 or later where the vulnerability has been patched.
3
What type of vulnerability is CVE-2020-21345?
CVE-2020-21345 is a Cross Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2020-21345?
CVE-2020-21345 affects all users of Halo version 1.1.3.
5
What can an attacker do with CVE-2020-21345?
An attacker exploiting CVE-2020-21345 can execute arbitrary code in the context of an affected user.