CVE-2014-9528: SQL Injection
SQL injection vulnerability in the actionIndex function in protected/modulescore/notification/controllers/ListController.php in HumHub 0.10.0-rc.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the from parameter to index.php. NOTE: this can be leveraged for cross-site scripting (XSS) attacks via a request that causes an error.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9528?
CVE-2014-9528 is considered a high severity SQL injection vulnerability that can allow unauthorized data access.
How do I fix CVE-2014-9528?
To fix CVE-2014-9528, update HumHub to version 0.10.0 or later.
What types of attacks can be performed using CVE-2014-9528?
CVE-2014-9528 allows attackers to execute arbitrary SQL commands, potentially leading to data compromise.
Who is affected by CVE-2014-9528?
CVE-2014-9528 affects users of HumHub versions 0.10.0-rc.1 and earlier, particularly those with authenticated access.
What software versions are vulnerable to CVE-2014-9528?
HumHub versions up to and including 0.10.0-rc.1 are vulnerable to CVE-2014-9528.