CVE-2024-56156: Halo Vulnerable to Stored XSS and RCE via File Upload Bypass
Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enables the upload of malicious files including executables and HTML files, which can lead to stored cross-site scripting attacks and potential remote code execution under certain circumstances. This issue has been patched in version 2.20.13.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56156?
CVE-2024-56156 has a moderate severity level due to its potential for allowing the upload of malicious files.
How do I fix CVE-2024-56156?
To fix CVE-2024-56156, upgrade Halo to version 2.20.13 or higher.
What types of attacks are possible due to CVE-2024-56156?
CVE-2024-56156 could lead to stored cross-site scripting and the execution of malicious files.
What versions of Halo are affected by CVE-2024-56156?
CVE-2024-56156 affects all versions of Halo prior to 2.20.13.
Is it safe to use Halo after fixing CVE-2024-56156?
Yes, after updating Halo to version 2.20.13 or later, it is safe to use the application.