PT-2026-57054 · Halo Dev · Halo
CVSS v2.0
4.7
Medium
| Vector | AV:N/AC:L/Au:M/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
halo-dev halo versions prior to 2.24.3
Description
A path traversal issue exists in the Theme Installation component within the
ThemeUtils.unzipThemeTo() function of the ThemeUtils.java file. This occurs when the metadata.name argument is manipulated, allowing a remote attacker to perform path traversal, which is a method used to access files and directories that are stored outside the intended folder.Recommendations
Update halo-dev halo to a version newer than 2.24.2.
As a temporary mitigation, restrict the use of the
ThemeUtils.unzipThemeTo() function until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Halo