Vulnerabilities
Vulnerable Software
Halo:  >> Halo  >> 1.2.0  Security Vulnerabilities
Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.
CVSS Score
5.4
EPSS Score
0.002
Published
2020-08-26
Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.
CVSS Score
7.2
EPSS Score
0.004
Published
2019-12-26


Contact Us

Shodan ® - All rights reserved