PT-2022-15259 · Halo · Halo

Ruibaby

·

Published

2022-01-13

·

Updated

2022-01-14

·

CVE-2022-22123

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Halo versions v1.0.0 through v1.4.17
Description The issue concerns Stored Cross-Site Scripting (XSS) in the article title, allowing an authenticated attacker to inject arbitrary javascript code that will execute on a victim’s server.
Recommendations For versions v1.0.0 through v1.4.17, consider restricting access to the article title feature until a patch is available, and avoid using the article title field for any sensitive operations. As a temporary workaround, consider validating and sanitizing all user input in the article title to prevent the injection of malicious javascript code.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22123

Affected Products

Halo