HaloITSM是英国HaloITSM公司的一款符合 ITIL 的 ITSM 软件。 HaloITSM 2.146.1版本及之前版本存在安全漏洞,该漏洞源于受到SAML XML签名包装漏洞的影响,配置SAML集成后,匿名参与者只需知道电子邮件地址即可冒充任意HaloITSM用户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Halo Service Solutions | HaloITSM | < 2.146.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-6203 | 8.3 HIGH | HaloITSM - Password Reset Poisoning |
| CVE-2024-6200 | 8.0 HIGH | HaloITSM - Stored Cross-Site Scripting in Tickets |
| CVE-2024-6201 | 5.3 MEDIUM | HaloITSM - Emailing Template Injection |
No comments yet