CVE-2024-43793

MEDIUM

Halo < 2.19.0 - XSS

Title source: rule
STIX 2.1

Description

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the user's browser through specific HTML and JavaScript code, potentially leading to a Cross-Site Scripting (XSS) attack. This vulnerability is fixed in 2.19.0.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://github.com/halo-dev/halo/security/advisories/GHSA-28x9-hppj-m537

Scores

CVSS v3 6.3
EPSS 0.0012
EPSS Percentile 30.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
halo/halo < 2.19.0
Published Sep 11, 2024
Tracked Since Feb 18, 2026