Show filters
50 Total Results
Displaying 11-20 of 50
Sort by:
Attacker Value
Unknown

CVE-2023-27164

Disclosure Date: March 10, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.
Attacker Value
Unknown

CVE-2022-36784

Disclosure Date: November 17, 2022 (last updated October 26, 2023)
Elsight – Elsight Halo  Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution.
Attacker Value
Unknown

CVE-2022-32995

Disclosure Date: June 27, 2022 (last updated October 07, 2023)
Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.
Attacker Value
Unknown

CVE-2022-32994

Disclosure Date: June 27, 2022 (last updated October 07, 2023)
Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.
Attacker Value
Unknown

CVE-2022-28074

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools.
Attacker Value
Unknown

CVE-2022-26619

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.
Attacker Value
Unknown

CVE-2021-43659

Disclosure Date: March 24, 2022 (last updated February 23, 2025)
In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS vulnerability.
Attacker Value
Unknown

CVE-2022-22125

Disclosure Date: January 11, 2022 (last updated February 23, 2025)
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An authenticated admin attacker can inject arbitrary javascript code that will execute on a victim’s server.
0
Attacker Value
Unknown

CVE-2022-22123

Disclosure Date: January 11, 2022 (last updated February 23, 2025)
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. An authenticated attacker can inject arbitrary javascript code that will execute on a victim’s server.
Attacker Value
Unknown

CVE-2022-22124

Disclosure Date: January 11, 2022 (last updated February 23, 2025)
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can upload a carefully crafted SVG file that will trigger arbitrary javascript to run on a victim’s browser.
0