CVE-2022-32994: Malicious File Upload
Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32994?
CVE-2022-32994 has a high severity due to the potential for arbitrary file uploads, which can lead to remote code execution.
How does CVE-2022-32994 affect Halo CMS?
CVE-2022-32994 affects Halo CMS v1.5.3 by allowing unauthorized users to upload arbitrary files through the /api/admin/attachments/upload endpoint.
What are the potential impacts of CVE-2022-32994?
The potential impacts of CVE-2022-32994 include data compromise, service disruption, and the ability to execute malicious code on the server.
How do I fix CVE-2022-32994?
To fix CVE-2022-32994, users should upgrade Halo CMS to the latest version that has addressed this vulnerability.
Is CVE-2022-32994 being exploited in the wild?
As of the latest updates, there have been reports indicating that CVE-2022-32994 is actively being exploited, highlighting the urgency to patch.