Описание
HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, the attacker would need a permission to administer the Spaces feature. The names of individual "spaces" are not properly escaped and so an attacker with sufficient privilege could insert malicious javascript into a space name and exploit system users who visit that space. It is recommended that the HumHub is upgraded to 1.11.4, 1.10.5. There are no known workarounds for this issue.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Not Applicable
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Not Applicable
Уязвимые конфигурации
Конфигурация 1Версия до 1.10.5 (исключая)Версия от 1.11.0 (включая) до 1.11.4 (исключая)
Одно из
cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:*
cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00302
Низкий
5.9 Medium
CVSS3
4.8 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
EPSS
Процентиль: 53%
0.00302
Низкий
5.9 Medium
CVSS3
4.8 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79