Impact
The vulnerability is a Server‑Side Request Forgery in Halo version 2.22.14. At the /themes/-/install-from-uri endpoint, an authenticated user can craft a GET request that forces the server to retrieve arbitrary internal URLs. Because the request originates from the server, it can access resources that are normally protected by the internal network, leading to potential information disclosure. The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of fewer than 1% suggests a low likelihood of widespread exploitation at present.
Affected Systems
The flaw affects Halo, the web‑based content management system, specifically the 2.22.14 release. No other versions are mentioned as vulnerable in the data provided.
Risk and Exploitability
Authenticated attackers can use the SSRF to scan internal hosts, such as discovery services, databases, or other services exposed only within the private network. Although the EPSS score is very low and the vulnerability is not listed in the CISA KEV catalog, environments that expose Halo to internal services remain at risk of internal enumeration and potential lateral movement. The attacker must have valid credentials; however, once authenticated, routine administrative actions could be leveraged to trigger outbound requests, exposing the network’s internal topology.
OpenCVE Enrichment