vendor:
HumHub
by:
Eric Sesterhenn
7,5
CVSS
HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
89
CWE
Product Name: HumHub
Affected Version From: HumHub 0.11.2
Affected Version To: HumHub 0.20.0-beta.2
Patch Exists: NO
Related CWE: N/A
CPE: a:humhub:humhub
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
HumHub – SQL-Injection
Enables to read and modify the HumHub Mysql Database. While conducting an internal software evaluation, LSE Leading Security Experts GmbH discovered that the humhub social networking software is subject to an sql-injection attack.
Mitigation:
Block access to the humhub software until the vendor provides a patch.