Loading
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. An authenticated attacker can inject arbitrary javascript code that will execute on a victim’s server.
Cite this page
CVE-2022-22123. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-22123
Use CWE-79, Fit2cloud vendor hub and Halo product page to widen CVE-2022-22123 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-22124, CVE-2022-28074 and CVE-2025-14117 for nearby disclosures in the same product family.