PT-2025-17926 · Halo · Halo
Published
2025-04-25
·
Updated
2026-02-03
·
CVE-2024-56156
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Halo versions prior to 2.20.13
Description
The issue allows attackers to bypass file type validation controls, enabling the upload of malicious files, including executables and HTML files. This can lead to stored cross-site scripting attacks and potential remote code execution under certain circumstances.
Recommendations
For versions prior to 2.20.13, update to version 2.20.13 to resolve the issue. As a temporary workaround, consider restricting file uploads to minimize the risk of exploitation. Avoid using the file upload feature until the issue is resolved.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Halo