CVE-2023-27164 Information

Description

An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.

Reference

https://github.com/halo-dev/halo https://notes.sjtu.edu.cn/s/s5oEvs-p5 http://halo.com

Share on: