PT-2025-17926 · Halo · Halo

Published

2025-04-25

·

Updated

2026-02-03

·

CVE-2024-56156

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Halo versions prior to 2.20.13
Description The issue allows attackers to bypass file type validation controls, enabling the upload of malicious files, including executables and HTML files. This can lead to stored cross-site scripting attacks and potential remote code execution under certain circumstances.
Recommendations For versions prior to 2.20.13, update to version 2.20.13 to resolve the issue. As a temporary workaround, consider restricting file uploads to minimize the risk of exploitation. Avoid using the file upload feature until the issue is resolved.

Exploit

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-56156
GHSA-99MC-CH53-PQH9

Affected Products

Halo