by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
14 packages
- eschalot
- python312Packages.halo
- python313Packages.halo
- python314Packages.halo
- typstPackages.whalogen
- python312Packages.halohome
- python313Packages.halohome
- python314Packages.halohome
- typstPackages.whalogen_0_1_0
- typstPackages.whalogen_0_2_0
- typstPackages.whalogen_0_3_0
- python312Packages.django-cachalot
- python313Packages.django-cachalot
- python314Packages.django-cachalot
- @LeSuisse dismissed
Halo Vulnerable to Stored XSS and RCE via File Upload Bypass
Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enables the upload of malicious files including executables and HTML files, which can lead to stored cross-site scripting attacks and potential remote code execution under certain circumstances. This issue has been patched in version 2.20.13.
References
-
https://github.com/halo-dev/halo/security/advisories/GHSA-99mc-ch53-pqh9 x_refsource_CONFIRM
-
https://github.com/halo-dev/halo/pull/7149 x_refsource_MISC
Affected products
- ==< 2.20.13
Matching in nixpkgs
Ignored packages (14)
pkgs.eschalot
Tor hidden service name generator
-
nixos-unstable 1.2.0.20191006
- nixpkgs-unstable 1.2.0.20191006
- nixos-unstable-small 1.2.0.20191006
pkgs.python312Packages.halo
None
pkgs.python313Packages.halo
Beautiful Spinners for Terminal, IPython and Jupyter
pkgs.python314Packages.halo
Beautiful Spinners for Terminal, IPython and Jupyter
pkgs.typstPackages.whalogen
None
pkgs.python312Packages.halohome
None
pkgs.python313Packages.halohome
Python library to control Eaton HALO Home Smart Lights
pkgs.python314Packages.halohome
Python library to control Eaton HALO Home Smart Lights
pkgs.typstPackages.whalogen_0_1_0
Typesetting chemical formulae, a port of mhchem
pkgs.typstPackages.whalogen_0_2_0
Typesetting chemical formulae, a port of mhchem
pkgs.typstPackages.whalogen_0_3_0
Typesetting chemical formulae, a port of mhchem
pkgs.python312Packages.django-cachalot
None
pkgs.python313Packages.django-cachalot
No effort, no worry, maximum performance
pkgs.python314Packages.django-cachalot
No effort, no worry, maximum performance