{"id":"CVE-2020-19007","details":"Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.","modified":"2026-08-07T15:10:56.989880Z","published":"2020-08-26T14:15:10.637Z","references":[{"type":"REPORT","url":"https://github.com/halo-dev/halo/issues/547"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/halo-dev/halo","events":[{"introduced":"2203889fe70e6ca21937f1e38c9b1bce7ef36910"},{"last_affected":"2203889fe70e6ca21937f1e38c9b1bce7ef36910"}],"database_specific":{"cpe":"cpe:2.3:a:halo:halo:1.2.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.2.0"},{"last_affected":"1.2.0"}],"source":"CPE_STRING"}}],"versions":["1.2.0","v1.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-19007.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}