CVE-2019-9093: XSS
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in file/file/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing a JavaScript payload in the filename parameter is echoed back, which resulted in reflected XSS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9093?
The severity of CVE-2019-9093 is medium with a CVSS score of 6.1.
What is the vulnerability description of CVE-2019-9093?
CVE-2019-9093 is a Reflected Cross Site Scripting (XSS) vulnerability in Humhub 1.3.10 Community Edition. The vulnerability allows user-supplied input containing a JavaScript payload in the filename parameter to be echoed back, resulting in a reflected XSS attack.
How does CVE-2019-9093 affect Humhub?
CVE-2019-9093 affects Humhub 1.3.10 Community Edition.
How can I fix CVE-2019-9093?
To fix CVE-2019-9093, update your Humhub installation to the latest version.
Where can I find more information about CVE-2019-9093?
More information about CVE-2019-9093 can be found at the following link: https://github.com/humhub/humhub/blob/master/protected/humhub/docs/CHANGELOG.md