Логотип exploitDog
bind:CVE-2020-19007
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-19007

Количество 2

Количество 2

nvd логотип

CVE-2020-19007

больше 5 лет назад

Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-j97g-76wm-6mpj

больше 3 лет назад

Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-19007

Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.

CVSS3: 5.4
0%
Низкий
больше 5 лет назад
github логотип
GHSA-j97g-76wm-6mpj

Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу