CVE-2020-18980: Critical severity halo vulnerability
Published Jul 12, 2021
·Updated
Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.
Affected Software
1 affected component
Halo Halo=0.4.3
Event History
Jul 12, 2021
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-18980?
CVE-2020-18980 has a severity rating of high due to its ability to allow remote code execution.
2
How do I fix CVE-2020-18980?
To fix CVE-2020-18980, upgrade Halo to version 0.4.4 or later where the vulnerability has been patched.
3
What does CVE-2020-18980 exploit?
CVE-2020-18980 exploits the remoteAddr and themeName parameters in Halo 0.4.3.
4
Who is affected by CVE-2020-18980?
Users and systems running Halo version 0.4.3 are affected by CVE-2020-18980.
5
Can CVE-2020-18980 be exploited without authentication?
Yes, CVE-2020-18980 can be exploited remotely which means that authentication is not required to perform the attack.