Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing attackers to redirect users to malicious websites (Open Redirect) and inject JavaScript code to perform cross site scripting attack.
The vulnerability affects Halo versions up to 2.174.101 and all versions between 2.175.1 and 2.184.21
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://support.haloservicedesk.com/kb?id=2501 |
![]() ![]() |
History
Thu, 08 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 08 May 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing attackers to redirect users to malicious websites (Open Redirect) and inject JavaScript code to perform cross site scripting attack. The vulnerability affects Halo versions up to 2.174.101 and all versions between 2.175.1 and 2.184.21 | |
Title | HaloITSM open redirect via the returnUrl | |
Weaknesses | CWE-20 CWE-601 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: NCSC.ch
Published: 2025-05-08T08:15:06.510Z
Updated: 2025-05-08T14:07:49.368Z
Reserved: 2025-04-16T08:59:30.459Z
Link: CVE-2025-40846

Updated: 2025-05-08T14:07:39.744Z

Status : Awaiting Analysis
Published: 2025-05-08T09:15:20.320
Modified: 2025-05-08T14:39:09.683
Link: CVE-2025-40846

No data.