Skip to content

Improper access control when user is forced to change password

Critical
luke- published GHSA-2h35-f226-3f57 Apr 19, 2022

Package

Core (Core)

Affected versions

< 1.8

Patched versions

1.11.0, 1.10.4, 1.9.4

Description

Impact

Users who were forced to change their password by an administrator could perform unauthorized actions and retrieve other users' data.

Patches

It is recommended that the HumHub is upgraded to 1.11.0, 1.10.4 or 1.9.4.

References

For more information

If you have any questions or comments about this advisory:

  • Create a post in our Community
  • Customers: Open a support ticket

Severity

Critical

CVE ID

CVE-2022-24865

Weaknesses