Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
halo halo vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2019-19999
Halo prior to 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.
Halo Halo
Halo Halo 1.1.3
Halo Halo 1.2.0
4.8
CVSSv3
CVE-2023-27164
An arbitrary file upload vulnerability in Halo up to v1.6.1 allows malicious users to execute arbitrary code via a crafted .md file.
Halo Halo
4.8
CVSSv3
CVE-2022-22125
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An authenticated admin attacker can inject arbitrary javascript code that will execute on a victim’s server.
Halo Halo
7.5
CVSSv3
CVE-2020-23079
SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.
Halo Halo
5.4
CVSSv3
CVE-2020-19007
Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.
Halo Halo 1.2.0
5.3
CVSSv3
CVE-2020-19037
Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies.
Halo Halo 0.4.3
9.1
CVSSv3
CVE-2020-19038
File Deletion vulnerability in Halo 0.4.3 via delBackup.
Halo Halo 0.4.3
9.8
CVSSv3
CVE-2022-32994
Halo CMS v1.5.3 exists to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.
Halo Halo 1.5.3
9.8
CVSSv3
CVE-2022-32995
Halo CMS v1.5.3 exists to contain a Server-Side Request Forgery (SSRF) via the template remote download function.
Halo Halo 1.5.3
9.8
CVSSv3
CVE-2020-18980
Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.
Halo Halo 0.4.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3581
reflected XSS
CVE-2024-26925
CVE-2024-27956
LFI
CVE-2024-3607
CVE-2024-3107
CVE-2024-3295
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »