Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kingz40O

Researcher fromChaitin Tech
#18668of 53,635
14.4Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2021-10272
5.3
2021-07-12
Halo · Halo · CVE-2020-19037
Name of the Vulnerable Software and Affected Versions: Halo version 0.4.3 Description: The issue allows a malicious user to bypass encryption and view encrypted articles via cookies, due to an Incorrect Access Control vulnerability. Recommendations: For Halo version 0.4.3, update to a version that addresses the Incorrect Access Control issue to prevent unauthorized access to encrypted articles.
PT-2021-10273
9.1
2021-07-12
Halo · Halo · CVE-2020-19038
Name of the Vulnerable Software and Affected Versions: Halo version 0.4.3 Description: A File Deletion issue exists via the delBackup function. Recommendations: For Halo version 0.4.3, consider restricting access to the delBackup function as a temporary workaround until a patch is available.