CVE-2022-32995: SSRF
Published Jun 27, 2022
·Updated
Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.
Affected Software
1 affected component
Halo Halo=1.5.3
Event History
Jun 27, 2022
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-32995?
The severity of CVE-2022-32995 is critical with a CVSS score of 9.8.
2
How does Halo CMS v1.5.3 vulnerability CVE-2022-32995 occur?
Halo CMS v1.5.3 vulnerability CVE-2022-32995 occurs due to a Server-Side Request Forgery (SSRF) in the template remote download function.
3
What software version is affected by CVE-2022-32995?
The software version affected by CVE-2022-32995 is Halo CMS v1.5.3.