Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54441 | Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enables the upload of malicious files including executables and HTML files, which can lead to stored cross-site scripting attacks and potential remote code execution under certain circumstances. This issue has been patched in version 2.20.13. |
Tue, 03 Feb 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 19 Sep 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Halo
Halo halo |
|
| CPEs | cpe:2.3:a:halo:halo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Halo
Halo halo |
|
| Metrics |
cvssV3_1
|
Fri, 25 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Apr 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enables the upload of malicious files including executables and HTML files, which can lead to stored cross-site scripting attacks and potential remote code execution under certain circumstances. This issue has been patched in version 2.20.13. | |
| Title | Halo Vulnerable to Stored XSS and RCE via File Upload Bypass | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-03T18:07:18.738Z
Reserved: 2024-12-17T18:16:49.853Z
Link: CVE-2024-56156
Updated: 2025-04-25T20:14:48.908Z
Status : Modified
Published: 2025-04-25T16:15:25.597
Modified: 2026-02-03T19:16:10.857
Link: CVE-2024-56156
No data.
OpenCVE Enrichment
No data.
EUVD