CVE-2022-22125
- EPSS 0.83%
- Veröffentlicht 13.01.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:46:13
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An authenticated admin attacker can inject arbitrary javascript code that will execute on a victim’s server.
CVE-2020-23079
- EPSS 1.24%
- Veröffentlicht 12.07.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:13:34
SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.
CVE-2020-19038
- EPSS 1.17%
- Veröffentlicht 12.07.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:55
File Deletion vulnerability in Halo 0.4.3 via delBackup.
CVE-2020-19037
- EPSS 0.89%
- Veröffentlicht 12.07.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:55
Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies.
CVE-2020-18982
- EPSS 0.57%
- Veröffentlicht 12.07.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:53
Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl.
CVE-2020-18980
- EPSS 1.46%
- Veröffentlicht 12.07.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:53
Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.
CVE-2020-18979
- EPSS 0.74%
- Veröffentlicht 12.07.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:08:53
Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via the X-forwarded-for Header parameter.
CVE-2020-21345
- EPSS 0.81%
- Veröffentlicht 20.05.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:31
Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a remote malicious user execute arbitrary code.
CVE-2020-21527
- EPSS 1.12%
- Veröffentlicht 30.09.2020 18:15:24
- Zuletzt bearbeitet 21.11.2024 05:12:39
There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, when deleting their backup files, to delete any files on the system through directory traversal.
CVE-2020-21524
- EPSS 1.51%
- Veröffentlicht 30.09.2020 18:15:24
- Zuletzt bearbeitet 21.11.2024 05:12:39
There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the background(/api/admin/migrations/wordpress) needs to parse the xml file, but it is not used for security defense, This vulnerability can d...