CVE-2021-43847

HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.
References
Link Resource
https://github.com/humhub/humhub/pull/5473 Patch Third Party Advisory
https://github.com/humhub/humhub/releases/tag/v1.10.3 Release Notes Third Party Advisory
https://github.com/humhub/humhub/releases/tag/v1.9.3 Release Notes Third Party Advisory
https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74 Exploit Third Party Advisory
https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/ Exploit Issue Tracking Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:*
cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-12-20 22:15

Updated : 2024-02-28 18:48


NVD link : CVE-2021-43847

Mitre link : CVE-2021-43847

CVE.ORG link : CVE-2021-43847


JSON object : View

Products Affected

humhub

  • humhub
CWE
CWE-862

Missing Authorization

CWE-285

Improper Authorization