RSS   Vulnerabilities for 'HALO'   RSS

2022-01-13
 
CVE-2022-22123

CWE-79
 

 
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. An authenticated attacker can inject arbitrary javascript code that will execute on a victim�??s server.

 
 
CVE-2022-22124

CWE-79
 

 
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can upload a carefully crafted SVG file that will trigger arbitrary javascript to run on a victim�??s browser.

 


Copyright 2024, cxsecurity.com

 

Back to Top