Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

T-Pod

#44047of 53,622
6.1Total CVSS
Vulnerabilities · 1
PT-2021-10613
6.1
2021-05-20
Halo · Halo · CVE-2020-21345
Name of the Vulnerable Software and Affected Versions: Halo version 1.1.3 Description: The issue is related to a Cross Site Scripting (XSS) vulnerability, which allows a remote malicious user to execute arbitrary code via post publish components in the manage panel. Recommendations: For Halo version 1.1.3, as a temporary workaround, consider disabling the post publish components in the manage panel until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.