CVE-2019-11564

A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/data/app/view/index.php POST request.
References
Link Resource
https://www.exploit-db.com/exploits/46771/ Exploit Third Party Advisory
https://humhub.org/en/news Release Notes Vendor Advisory
Configurations

Configuration 1

cpe:2.3:a:humhub:humhub:1.3.12:*:*:*:*:*:*:*

Information

Published : 2019-05-08 04:29

Updated : 2019-05-08 06:20


NVD link : CVE-2019-11564

Mitre link : CVE-2019-11564

Products Affected
No products.
CWE