CVE-2021-43847: Authorization Bypass in Space Invite in HumHub
HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is HumHub?
HumHub is an open-source social network kit written in PHP.
What is the vulnerability ID for this HumHub vulnerability?
The vulnerability ID for this HumHub vulnerability is CVE-2021-43847.
What is the severity of CVE-2021-43847?
The severity of CVE-2021-43847 is medium with a CVSS score of 6.5.
How can registered users become unauthorized members of private Spaces in HumHub?
Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces.
How can I fix the vulnerability in HumHub?
To fix the vulnerability, update HumHub to version 1.10.3 or 1.9.3 which contain a patch for this issue.
Are there any references related to this HumHub vulnerability?
Yes, you can find more information about this vulnerability in the following references: [GitHub Pull Request](https://github.com/humhub/humhub/pull/5473), [HumHub Releases](https://github.com/humhub/humhub/releases/tag/v1.10.3), [HumHub Releases](https://github.com/humhub/humhub/releases/tag/v1.9.3).
What are the Common Weakness Enumerations (CWE) associated with this HumHub vulnerability?
The Common Weakness Enumerations (CWE) associated with this HumHub vulnerability are CWE-862 and CWE-285.