CVE-2021-43847
Summary
| CVE | CVE-2021-43847 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-20 22:15:00 UTC |
| Updated | 2022-08-09 13:27:00 UTC |
| Description | HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| huntr – the Bug Bounty Platform for any GitHub repository | MISC | huntr.dev | |
| Authorization Bypass in Space Invite · Advisory · humhub/humhub · GitHub | CONFIRM | github.com | |
| Release 1.10.3 · humhub/humhub · GitHub | MISC | github.com | |
| Improved Invitation by yurabakhtin · Pull Request #5473 · humhub/humhub · GitHub | MISC | github.com | |
| Release 1.9.3 · humhub/humhub · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.