Product
Halo versions up to 2.25.4 are vulnerable to RCE through insecure plugin installation and migration restoration processes, which can be chained with CSRF to allow unauthenticated attackers to compromise an instance if an administrator visits a malicious page.