CVE-2021-43847

HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:*
cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:29

Type Values Removed Values Added
References () https://github.com/humhub/humhub/pull/5473 - Patch, Third Party Advisory () https://github.com/humhub/humhub/pull/5473 - Patch, Third Party Advisory
References () https://github.com/humhub/humhub/releases/tag/v1.10.3 - Release Notes, Third Party Advisory () https://github.com/humhub/humhub/releases/tag/v1.10.3 - Release Notes, Third Party Advisory
References () https://github.com/humhub/humhub/releases/tag/v1.9.3 - Release Notes, Third Party Advisory () https://github.com/humhub/humhub/releases/tag/v1.9.3 - Release Notes, Third Party Advisory
References () https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74 - Exploit, Third Party Advisory () https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74 - Exploit, Third Party Advisory
References () https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/ - Exploit, Issue Tracking, Patch, Third Party Advisory () https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/ - Exploit, Issue Tracking, Patch, Third Party Advisory

09 Aug 2022, 13:27

Type Values Removed Values Added
CWE CWE-285 CWE-862

03 Jan 2022, 18:34

Type Values Removed Values Added
CPE cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 6.5
v2 : 4.0
v3 : 6.5
References (CONFIRM) https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74 - (CONFIRM) https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74 - Exploit, Third Party Advisory
References (MISC) https://github.com/humhub/humhub/releases/tag/v1.10.3 - (MISC) https://github.com/humhub/humhub/releases/tag/v1.10.3 - Release Notes, Third Party Advisory
References (MISC) https://github.com/humhub/humhub/releases/tag/v1.9.3 - (MISC) https://github.com/humhub/humhub/releases/tag/v1.9.3 - Release Notes, Third Party Advisory
References (MISC) https://github.com/humhub/humhub/pull/5473 - (MISC) https://github.com/humhub/humhub/pull/5473 - Patch, Third Party Advisory
References (MISC) https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/ - (MISC) https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/ - Exploit, Issue Tracking, Patch, Third Party Advisory

20 Dec 2021, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-20 22:15

Updated : 2024-11-21 06:29


NVD link : CVE-2021-43847

Mitre link : CVE-2021-43847

CVE.ORG link : CVE-2021-43847


JSON object : View

Products Affected

humhub

  • humhub
CWE
CWE-285

Improper Authorization

CWE-862

Missing Authorization