Halo

Halo

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.33%
  • Veröffentlicht 11.09.2024 15:15:17
  • Zuletzt bearbeitet 16.09.2024 16:28:45

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the user's browser through specific HTML...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 02.09.2024 18:15:35
  • Zuletzt bearbeitet 16.09.2024 16:26:18

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the user's browser through specific HTML...

  • EPSS 0.31%
  • Veröffentlicht 28.03.2024 23:15:46
  • Zuletzt bearbeitet 28.03.2025 19:15:16

halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).

Exploit
  • EPSS 0.7%
  • Veröffentlicht 10.03.2023 16:15:11
  • Zuletzt bearbeitet 21.11.2024 07:52:24

An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.

Exploit
  • EPSS 15.91%
  • Veröffentlicht 27.06.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 07:07:22

Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.

Exploit
  • EPSS 16.73%
  • Veröffentlicht 27.06.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 07:07:22

Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.

Exploit
  • EPSS 0.87%
  • Veröffentlicht 05.04.2022 01:15:09
  • Zuletzt bearbeitet 21.11.2024 06:54:12

Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.

Exploit
  • EPSS 0.54%
  • Veröffentlicht 24.03.2022 14:15:09
  • Zuletzt bearbeitet 21.11.2024 06:29:33

In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS vulnerability.

Exploit
  • EPSS 0.83%
  • Veröffentlicht 13.01.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:46:13

In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An authenticated admin attacker can inject arbitrary javascript code that will execute on a victim’s server.

Exploit
  • EPSS 1.24%
  • Veröffentlicht 12.07.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 05:13:34

SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.