humhub.org
https://humhub.org/en/news CVE-2019-11564
MEDIUM
HumHub 1.3.12 - Cross-Site Scripting
Record summary
CVE-2019-11564 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/data/app/view/index.php POST request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHumHub 1.3.12 - Cross-Site ScriptingExploitDB exploitby Kağan EĞLENCENot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-11564 exploit-db.com
https://www.exploit-db.com/exploits/46771