Loading
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can upload a carefully crafted SVG file that will trigger arbitrary javascript to run on a victim’s browser.
Cite this page
CVE-2022-22124. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-22124
Use CWE-79, Fit2cloud vendor hub and Halo product page to widen CVE-2022-22124 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-22123, CVE-2022-28074 and CVE-2025-14117 for nearby disclosures in the same product family.