{"api_version":"1","generated_at":"2026-07-23T11:55:14+00:00","cve":"CVE-2021-43847","urls":{"html":"https://cve.report/CVE-2021-43847","api":"https://cve.report/api/cve/CVE-2021-43847.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-43847","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-43847"},"summary":{"title":"CVE-2021-43847","description":"HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2021-12-20 22:15:00","updated_at":"2022-08-09 13:27:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/","name":"https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/","refsource":"MISC","tags":[],"title":"huntr – the Bug Bounty Platform for any GitHub repository","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74","name":"https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74","refsource":"CONFIRM","tags":[],"title":"Authorization Bypass in Space Invite · Advisory · humhub/humhub · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/humhub/humhub/releases/tag/v1.10.3","name":"https://github.com/humhub/humhub/releases/tag/v1.10.3","refsource":"MISC","tags":[],"title":"Release 1.10.3 · humhub/humhub · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/humhub/humhub/pull/5473","name":"https://github.com/humhub/humhub/pull/5473","refsource":"MISC","tags":[],"title":"Improved Invitation by yurabakhtin · Pull Request #5473 · humhub/humhub · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/humhub/humhub/releases/tag/v1.9.3","name":"https://github.com/humhub/humhub/releases/tag/v1.9.3","refsource":"MISC","tags":[],"title":"Release 1.9.3 · humhub/humhub · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-43847","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43847","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"43847","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"humhub","cpe5":"humhub","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2021-43847","STATE":"PUBLIC","TITLE":"Authorization Bypass in Space Invite in HumHub"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"humhub","version":{"version_data":[{"version_value":">= 1.10.0, < 1.10.3"},{"version_value":"< 1.9.3"}]}}]},"vendor_name":"humhub"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-285: Improper Authorization"}]}]},"references":{"reference_data":[{"name":"https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74","refsource":"CONFIRM","url":"https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74"},{"name":"https://github.com/humhub/humhub/pull/5473","refsource":"MISC","url":"https://github.com/humhub/humhub/pull/5473"},{"name":"https://github.com/humhub/humhub/releases/tag/v1.10.3","refsource":"MISC","url":"https://github.com/humhub/humhub/releases/tag/v1.10.3"},{"name":"https://github.com/humhub/humhub/releases/tag/v1.9.3","refsource":"MISC","url":"https://github.com/humhub/humhub/releases/tag/v1.9.3"},{"name":"https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/","refsource":"MISC","url":"https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/"}]},"source":{"advisory":"GHSA-f5hc-5wfr-7v74","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-12-20 22:15:00","lastModifiedDate":"2022-08-09 13:27:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:*","versionStartIncluding":"1.10.0","versionEndExcluding":"1.10.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:*","versionEndExcluding":"1.9.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"43847","Ordinal":"221385","Title":"CVE-2021-43847","CVE":"CVE-2021-43847","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"43847","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}