Security Advisory
CVE-2025-44593
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnerability is fixed in 2.20.13