Description
HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails. This can lead to the leakage of potentially sensitive information. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47338 | HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails. This can lead to the leakage of potentially sensitive information. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability. |
References
| Link | Providers |
|---|---|
| https://haloitsm.com/guides/article/?kbid=2153 |
|
History
Thu, 29 Aug 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-Other |
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2025-03-25T16:42:00.570Z
Reserved: 2024-06-20T13:13:27.875Z
Link: CVE-2024-6201
Updated: 2024-08-06T14:18:12.388Z
Status : Analyzed
Published: 2024-08-06T06:15:35.283
Modified: 2024-08-29T17:52:07.493
Link: CVE-2024-6201
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD