CVE-2022-24865
Summary
| CVE | CVE-2022-24865 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-20 20:15:00 UTC |
| Updated | 2022-05-02 19:23:00 UTC |
| Description | HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`. It is recommended that the HumHub is upgraded to 1.11.0, 1.10.4 or 1.9.4. There are no known workarounds for this issue. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix must change password (#5638) · humhub/humhub@eb83de2 · GitHub | MISC | github.com | |
| Improper access control could make any user export all user of website vulnerability found in humhub | MISC | huntr.dev | |
| Improper access control when user is forced to change password · Advisory · humhub/humhub · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.