CVE-2025-44593
09.09.2025, 21:15
Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnerability is fixed in 2.20.13Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.