CVE-2025-15141: Halo Configuration actuator information disclosure
A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configuration Handler. Executing a manipulation can lead to information disclosure. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15141?
CVE-2025-15141 is classified as a potential information disclosure vulnerability.
How do I fix CVE-2025-15141?
To fix CVE-2025-15141, users should upgrade Halo Configuration Handler to version 2.21.11 or later.
What component is affected by CVE-2025-15141?
CVE-2025-15141 affects the Configuration Handler component of Halo.
Can CVE-2025-15141 be exploited remotely?
Yes, CVE-2025-15141 can be exploited remotely.
What is the impact of exploiting CVE-2025-15141?
Exploitation of CVE-2025-15141 can lead to information disclosure.