CVE-2024-6201
MEDIUMDescription
HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails. This can lead to the leakage of potentially sensitive information. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.
Is your site exposed to CVE-2024-6201?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| haloservicesolutions | haloitsm |
| haloservicesolutions | haloitsm |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-6201? +
How severe is CVE-2024-6201? +
What products are affected by CVE-2024-6201? +
How do I check if I'm vulnerable to CVE-2024-6201? +
Related Vulnerabilities
HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration …
HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent …
HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute …