VulnerabilityModified
CVE-2021-43847
Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces.
MEDIUM 6.5EPSS 1.18%
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285, CWE-862
- Affected
- humhub/humhub
- Source
- security-advisories@github.com
References
- https://github.com/humhub/humhub/pull/5473Patch, Third Party Advisory
- https://github.com/humhub/humhub/releases/tag/v1.10.3Release Notes, Third Party Advisory
- https://github.com/humhub/humhub/releases/tag/v1.9.3Release Notes, Third Party Advisory
- https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74Exploit, Third Party Advisory
- https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/humhub/humhub/pull/5473Patch, Third Party Advisory
- https://github.com/humhub/humhub/releases/tag/v1.10.3Release Notes, Third Party Advisory
- https://github.com/humhub/humhub/releases/tag/v1.9.3Release Notes, Third Party Advisory
- https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74Exploit, Third Party Advisory
- https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/Exploit, Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.