CVE-2022-31133
Summary
| CVE | CVE-2022-31133 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-07 18:15:00 UTC |
| Updated | 2022-07-14 19:03:00 UTC |
| Description | HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, the attacker would need a permission to administer the Spaces feature. The names of individual "spaces" are not properly escaped and so an attacker with sufficient privilege could insert malicious javascript into a space name and exploit system users who visit that space. It is recommended that the HumHub is upgraded to 1.11.4, 1.10.5. There are no known workarounds for this issue. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix format of displaying user profile title field on "People" page (#… · humhub/humhub@07d9f8f · GitHub | MISC | github.com | |
| XSS in Space Admin · Advisory · humhub/humhub · GitHub | CONFIRM | github.com | |
| Fix space name in membership confirmation (#5790) · humhub/humhub@f88991d · GitHub | MISC | github.com | |
| Improper access control could make any user export all user of website vulnerability found in humhub | MISC | huntr.dev | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.