Impact
The /plugins/{name}/upgrade-from-uri endpoint in Halo is vulnerable to Server-Side Request Forgery. A crafted GET request, when issued by an authenticated user, forces the server to fetch any URL the attacker specifies. The attacker can probe internal IP addresses, access protected services, and gather information about the internal network. This can enable further attacks if the scanned services have additional weaknesses.
Affected Systems
Halo CMS version 2.22.14. The documented vulnerability resides in the plugin upgrade-from-uri endpoint, affecting installations running this version or earlier that have not applied the fix.
Risk and Exploitability
Because authentication is required, only compromised or privileged accounts can exploit the flaw. The CVSS score is 4.3; the EPSS is not reported and the vulnerability is not listed in KEV, suggesting low to moderate exploitation likelihood. However, the ability to enumerate internal resources can be a stepping stone toward more serious attacks, so the risk is non-negligible for exposed or poorly segmented environments.
OpenCVE Enrichment