PT-2024-35101 · Humhub · Humhub

Erez Kalman

·

Published

2024-11-06

·

Updated

2024-11-08

·

CVE-2024-52043

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions HumHub versions through 1.16.2
Description The issue affects HumHub, allowing excavation through user enumeration due to an observable response discrepancy. This discrepancy can lead to the generation of error messages containing sensitive information. The estimated number of potentially affected devices is not specified. There is no information provided about real-world incidents where this issue was exploited. The vulnerability is related to the excavation of user information, potentially allowing attackers to enumerate users.
Recommendations For versions through 1.16.2, update to a version that contains a fix for this issue to prevent user enumeration and potential remote exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-52043
GHSA-3Q4W-RF2J-FX5X

Affected Products

Humhub