Back to News & Press

Press Release

Assetnote Identifies Critical Pre-Auth SQL Injection Vulnerability in Halo ITSM

Share on social

April 2, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Assetnote Identifies Critical Pre-Auth SQL Injection Vulnerability in Halo ITSM

Vulnerability could be exploited to read, modify, or insert data into critical IT support software

Queensland, Australia, April 2 2025

Assetnote, now a Searchlight Cyber company, has discovered a pre-authentication SQL injection vulnerability in the IT Support Management (ITSM) provider Halo. This vulnerability is critical because of the nature of the data held within the software, which includes IT support tickets often containing credentials or internal documentation. Halo has issued a patch for the vulnerability following Assetnote’s disclosure.

Assetnote investigated Halo ITSM after identifying it on its customers’ attack surfaces to ensure that it couldn’t be used as a point of compromise. There are currently around 1,000 cloud deployments of the software under the haloitsm.com domain, not accounting for on-premise deployments.

The researchers found that several areas of the code base are vulnerable to SQL injection, leading to a number of “close calls”, which were only being prevented by using strongly typed objects enforcing the integer type. However, in the course of the investigation the team identified a pre-authentication SQL Injection vulnerability that an attacker could exploit to read, modify, or insert data inside the database connected to Halo ITSM. All of the technical details of the vulnerability can be found on the Assetnote Security Research blog.

Shubham Shah, SVP of Engineering and Research at Searchlight, explained the potential consequences of the vulnerability: “As an IT Support Management tool, Halo is often integrated with various internal and external systems and cloud providers, as well as containing sensitive information such as configuration files and credentials. This means that an attacker could have used this vulnerability to compromise any of the integrated systems, obtain sensitive data stored on the system, or even add themselves as an administrator and take over the instance.”

The vulnerabilities identified by Assetnote have been patched in version 2.174.94, candidate version 2.184.23, and beta version 2.186.2, and on-premise customers should upgrade urgently. Read the full Assetnote Security Research Center blog.

ENDS

About Assetnote, a Searchlight Cyber company:

Founded in 2018, Assetnote provides industry-leading attack surface management and adversarial exposure validation solutions, helping organizations identify and remediate security vulnerabilities before they can be exploited. In January 2025, Assetnote was acquired by Searchlight Cyber. Combined, the companies form a holistic platform for combating external threats through Continuous Threat Exposure Management. Visit assetnote.io and slcyber.io for more information.

Related Press Releases

Searchlight Cyber Launches Preemptive Threat Exposure Management Platform to Help Organizations Outpace AI-Accelerated Attacks

Press Release

Read press release

August 12, 2026

Searchlight Cyber Launches Preemptive Threat Exposure Management Platform to Help Organizations Outpace AI-Accelerated Attacks

Searchlight Cyber Appoints Paul Ciesielski as Chief Revenue Officer

Press Release

Read press release

June 11, 2026

Searchlight Cyber Appoints Paul Ciesielski as Chief Revenue Officer

Searchlight Cyber Named a Finalist at the 2026 Cyber Risk Awards

Press Release

Read press release

April 27, 2026

Searchlight Cyber Named a Finalist at the 2026 Cyber Risk Awards

Searchlight Cyber Report: Ransomware Groups Claimed Record Number of Victims in 2025 with 30% Annual Increase

Press Release

Read press release

February 17, 2026

Searchlight Cyber Report: Ransomware Groups Claimed Record Number of Victims in 2025 with 30% Annual Increase

Searchlight Cyber Appoints Michael Gianarakis as CEO

Press Release

Read press release

February 4, 2026

Searchlight Cyber Appoints Michael Gianarakis as CEO

Searchlight Cyber Launches Ransomware File Explorer to Enable Pre-Emptive Detection of Leaked Data

Press Release

Read press release

January 22, 2026

Searchlight Cyber Launches Ransomware File Explorer to Enable Pre-Emptive Detection of Leaked Data

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient