CVE-2024-43793: Halo's editor has a stored XSS vulnerability
Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the user's browser through specific HTML and JavaScript code, potentially leading to a Cross-Site Scripting (XSS) attack. This vulnerability is fixed in 2.19.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43793?
The severity of CVE-2024-43793 is classified as high due to the potential for remote code execution in the user's browser.
How do I fix CVE-2024-43793?
To fix CVE-2024-43793, upgrade your Halo installation to version 2.19.0 or later.
What versions of Halo are affected by CVE-2024-43793?
CVE-2024-43793 affects all versions of Halo prior to 2.19.0.
Can CVE-2024-43793 be exploited remotely?
Yes, CVE-2024-43793 can be exploited remotely through malicious scripts executed in the user's browser.
What are the potential consequences of CVE-2024-43793?
The potential consequences of CVE-2024-43793 include unauthorized access to user data and the execution of arbitrary scripts in the context of the victim's browser.