Vulnerabilities > CVE-2022-22125 - Unspecified vulnerability in Halo
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An authenticated admin attacker can inject arbitrary javascript code that will execute on a victim’s server.
Vulnerable Configurations
References
- https://github.com/halo-dev/halo/blob/v1.4.17/src/main/java/run/halo/app/service/impl/PostServiceImpl.java#L500
- https://github.com/halo-dev/halo/blob/v1.4.17/src/main/java/run/halo/app/service/impl/PostServiceImpl.java#L500
- https://github.com/halo-dev/halo/issues/1557
- https://github.com/halo-dev/halo/issues/1557
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22125
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22125