CyberRota Analysis
AI-GeneratedHalo CMS versions up to 2.25.4 are vulnerable to a Cross-Site Request Forgery (CSRF) flaw in the CorsConfigurer.java and CsrfConfigurer.java components, enabling remote attackers to execute arbitrary code. Organizations using affected versions of Halo CMS should prioritize patching this vulnerability to mitigate the risk of unauthorized actions and potential system compromise. Immediate action is recommended for those managing web applications that rely on this content management system.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code.