CVE-2025-44593: XSS
Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnerability is fixed in 2.20.13
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44593?
CVE-2025-44593 is classified as a high-severity vulnerability due to its potential to allow the upload of malicious files.
How do I fix CVE-2025-44593?
To fix CVE-2025-44593, upgrade your Halo installation to version 2.20.13 or later.
What types of malicious files can be uploaded due to CVE-2025-44593?
CVE-2025-44593 allows the upload of malicious files such as .exe and .html files, which can trigger stored XSS vulnerabilities.
What versions of Halo are affected by CVE-2025-44593?
CVE-2025-44593 affects all versions of Halo prior to 2.20.13.
What are the risks associated with CVE-2025-44593?
The risks associated with CVE-2025-44593 include the potential for file uploads leading to malign execution and cross-site scripting attacks.