CVE-2019-9094: XSS
Published Mar 18, 2019
·Updated
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in /s/adada/cfiles/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing JavaScript in the filename is echoed back in JavaScript code, which resulted in XSS.
Affected Software
1 affected component
Humhub Humhub=1.3.10
Event History
Mar 18, 2019
CVE Published
via MITRE·10:06 PM
Data Sourced
via MITRE·10:06 PM
Description
Mar 21, 2019
Data Sourced
via NVD·04:01 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-9094?
CVE-2019-9094 is a Reflected Cross Site Scripting (XSS) Vulnerability discovered in Humhub 1.3.10 Community Edition.
2
What is the severity of CVE-2019-9094?
The severity of CVE-2019-9094 is medium with a severity value of 6.1.
3
How does CVE-2019-9094 affect Humhub?
CVE-2019-9094 allows for Reflected Cross Site Scripting (XSS) attacks in Humhub 1.3.10 Community Edition.
4
How can I fix CVE-2019-9094?
To fix CVE-2019-9094, update Humhub to a version that is not affected by this vulnerability.
5
Where can I find more information about CVE-2019-9094?
More information about CVE-2019-9094 can be found in the Humhub documentation change log.