Halo CMS Server-Side Request Forgery Vulnerability
Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in Halo CMS version 2.21. This vulnerability allows remote attackers to make the server send HTTP requests to URLs controlled by the attacker, including internal addresses. The issue arises in the Thumbnail via-uri endpoint, which lacks proper validation of user-supplied URIs before performing a GET request. The vulnerability can lead to the disclosure of internal URLs through a 307 redirect in the Location header.
Impact
Exploitation of this vulnerability allows for server-side request forgery, where an attacker can manipulate the server to make requests to internal or external resources, potentially leading to further exploitation or information disclosure.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
