CVE-2019-11564: XSS
A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/data/app/view/index.php POST request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11564?
CVE-2019-11564 is a cross-site scripting (XSS) vulnerability in HumHub 1.3.12.
How does CVE-2019-11564 affect HumHub?
CVE-2019-11564 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/data/app/view/index.php POST request.
What is the severity of CVE-2019-11564?
CVE-2019-11564 has a severity score of 6.1, which is categorized as medium.
How can I fix CVE-2019-11564?
To fix CVE-2019-11564, you should update to a version of HumHub that is not affected by this vulnerability.
Where can I find more information about CVE-2019-11564?
You can find more information about CVE-2019-11564 on the official HumHub website and the Exploit-DB website.