PT-2022-7900 · Humhub · Humhub
Tim Coen
·
Published
2022-06-09
·
Updated
2022-06-17
·
CVE-2017-20027
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HumHub versions up to 1.0.1
Description
A vulnerability was found in HumHub, allowing for cross site scripting (DOM) attacks. The manipulation can be launched remotely, affecting some unknown functionality. The issue has been disclosed to the public.
Recommendations
For HumHub versions up to 1.0.1, upgrade to version 1.1.1 to address this issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Humhub