Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-9528

SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListController.php in HumHub 0.10.0-rc.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the from parameter to index.php. NOTE: this can be leveraged for cross-site scripting (XSS) attacks via a request that causes an error.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.024
EPSS Ranking 84.4%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2014-9528
  • Humhub » Humhub » Version: 0.10.0
    cpe:2.3:a:humhub:humhub:0.10.0
  • Humhub » Humhub » Version: 0.9.0
    cpe:2.3:a:humhub:humhub:0.9.0


Contact Us

Shodan ® - All rights reserved