MEDIUM
Halo CMS - Stored Cross-Site Scripting (XSS) in Profile Image
Published Jan 13, 2022
5.4
MEDIUMCVSS 3.1
EPSS 0.71%
Description
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can upload a carefully crafted SVG file that will trigger arbitrary javascript to run on a victim’s browser.
Affected products
-
Affected
- ≥ unspecified, ≤ v1.4.17
- ≥ v1.0.0, < unspecified
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-27273 Advisory
- https://github.com/halo-dev/halo/blob/v1.4.17/src/main/java/run/halo/app/handler/file/FileHandler.java#L30 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/halo-dev/halo/issues/1575 x_refsource_MISCIssue TrackingThird Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22124 x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-27273 | Advisory | |
| https://github.com/halo-dev/halo/blob/v1.4.17/src/main/java/run/halo/app/handler/file/FileHandler.java#L30 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/halo-dev/halo/issues/1575 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22124 | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mend
Published Jan 13, 2022
Updated Sep 17, 2024
Reserved Dec 21, 2021
Link CVE-2022-22124
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data