Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-107681. PoCs published by LSE Leading Security Experts GmbH.
AI-analyzed exploit summary This advisory details a SQL injection vulnerability in HumHub versions 0.11.2 and 0.20.0-beta.2, where the 'from' parameter in the directory stream endpoint is vulnerable to exploitation. The proof of concept includes SQLMap commands demonstrating boolean-based blind, error-based, and time-based blind SQL injection techniques.
Description
HumHub 0.11.2/0.20.0-beta.2 - SQL Injection
Exploits (1)
This advisory details a SQL injection vulnerability in HumHub versions 0.11.2 and 0.20.0-beta.2, where the 'from' parameter in the directory stream endpoint is vulnerable to exploitation. The proof of concept includes SQLMap commands demonstrating boolean-based blind, error-based, and time-based blind SQL injection techniques.