Back

MEDIUM

Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files

Published Sep 9, 2025

Description

Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnerability is fixed in 2.20.13

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 9, 2025
Updated Sep 10, 2025
Reserved Apr 22, 2025
CISA Vulnrichment
Updated Sep 10, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner mitre
Published Sep 9, 2025
Updated Sep 10, 2025
Exploited since n/a
EUVD-2025-27586