Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2022-32995

Disclosure Date: June 27, 2022 (last updated October 07, 2023)
Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.
Attacker Value
Unknown

CVE-2022-32994

Disclosure Date: June 27, 2022 (last updated October 07, 2023)
Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.