Junglewise Threat Intelligence

CVE-2025-60898: Halo Halo CMS SSRF in Thumbnail via-uri endpoint

CVE-2025-60898 · Severity: medium · CVSS 5.8 · Published 2025-10-29

Technologies: Halo. Vendors: Halo.

Executive brief

A security vulnerability exists in Halo CMS, a content management system, specifically within its thumbnail generation feature. An unauthorized remote attacker can trick the server into making requests to internal systems or external websites that should be restricted. This could allow an attacker to map out internal network infrastructure or access sensitive information from internal services that are not intended to be public.

Technical details

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in the 'Thumbnail via-uri' endpoint of Halo CMS version 2.21. The root cause is a failure to adequately validate user-supplied URIs against an allowlist or blocklist before performing a server-side GET request. An attacker can exploit this by providing a malicious URI, causing the server to interact with internal network resources or external attacker-controlled infrastructure. The endpoint further facilitates information disclosure by returning a 307 redirect that may reveal internal URLs within the Location header. This vulnerability is reachable over the network without authentication.

Affected products

  • Halo Halo CMS 2.21

Timeline

  • 2025-10-29: advisory: NVD publication date

References

Related threats