Lucene search

K
osvGoogleOSV:CVE-2021-43659
HistoryMar 24, 2022 - 2:15 p.m.

CVE-2021-43659

2022-03-2414:15:09
Google
osv.dev
2
halo 1.4.14
uploading
avatar
stored xss vulnerability
software

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

24.8%

In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS vulnerability.

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

24.8%

Related for OSV:CVE-2021-43659