Vulnerabilities > Haloservicesolutions

DATE CVE VULNERABILITY TITLE RISK
2024-08-06 CVE-2024-6200 Cross-site Scripting vulnerability in Haloservicesolutions Haloitsm
HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability.
network
low complexity
haloservicesolutions CWE-79
5.4
2024-08-06 CVE-2024-6201 Unspecified vulnerability in Haloservicesolutions Haloitsm 2.143.8/2.144/2.146
HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails.
network
low complexity
haloservicesolutions
5.3
2024-08-06 CVE-2024-6202 Incorrect Authorization vulnerability in Haloservicesolutions Haloitsm
HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability.
network
low complexity
haloservicesolutions CWE-863
critical
9.8
2024-08-06 CVE-2024-6203 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Haloservicesolutions Haloitsm
HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability.
network
low complexity
haloservicesolutions CWE-640
8.1