Impact
This vulnerability is a cross‑site request forgery flaw in Halo CMS that allows an attacker to send crafted requests that bypass the site’s CSRF checks and trigger actions that execute arbitrary code on the server. The flaw originates in the CorsConfigurer.java and CsrfConfigurer.java components and is present in all releases up to 2.25.4. If exploited, the attacker could compromise the confidentiality, integrity, and availability of the entire CMS installation, potentially allowing full control over the hosted website.
Affected Systems
Affected systems are installations of Halo CMS version 2.25.4 or earlier. The flaw resides in the web application layer of the CMS. No other product versions are known to be impacted.
Risk and Exploitability
The vulnerability can be triggered remotely via HTTP requests that satisfy the target’s CSRF validation logic. EPSS score is < 1%, indicating a very low probability of exploitation, but the CVSS score of 9.3 indicates severe impact. The flaw is not listed in the CISA KEV catalog. Because it permits remote code execution, the potential impact is severe and the threat model suggests a high likelihood for attackers with sufficient resource motivation. Immediate remediation is strongly advised.
OpenCVE Enrichment