Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-24865

Опубликовано: 20 апр. 2022
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit eb83de20. It is recommended that the HumHub is upgraded to 1.11.0, 1.10.4 or 1.9.4. There are no known workarounds for this issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:*
Версия до 1.9.4 (исключая)
cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:*
Версия от 1.10.0 (включая) до 1.10.4 (исключая)

EPSS

Процентиль: 56%
0.00342
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-863

EPSS

Процентиль: 56%
0.00342
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-863