CVE Database
/

CVE-2025-40846

Back to search

CVE-2025-40846

Published: May 8, 2025

Modified: May 8, 2025

PUBLISHED

Description

Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing attackers to redirect users to malicious websites (Open Redirect) and inject JavaScript code to perform cross site scripting attack. The vulnerability affects Halo versions up to 2.174.101 and all versions between 2.175.1 and 2.184.21

VendorProductVersions

HaloITSM

ITSM

unaffected
>= 2.174.101
unaffected
>= 2.184.21

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now