CVE-2020-21524 is an XML External Entity (XXE) vulnerability affecting Halo v1.1.3, specifically within the WordPress blog import function at /api/admin/migrations/wordpress. This critical flaw, with a CVSS score of 9.1, allows unauthenticated attackers to perform various malicious actions, including internal network reconnaissance, arbitrary file reading, and denial-of-service attacks. While a proof-of-concept exploit exists on GitHub, there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.3CPE matchmatch criteria | cpe:2.3:a:halo:halo:1.1.3:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.