Humhub CFiles Module File Move Functionality Reflected Self-XSS Vulnerability

Vulnerability

A reflected self-cross-site scripting vulnerability has been identified in the Humhub CFiles module, specifically in versions through 0.16.9. The issue arises in the File Move functionality, which lacks proper validation, allowing the injection of arbitrary JavaScript. This injection can be executed in the context of the user's browser session.

Impact

Exploitation of this vulnerability allows for the injection and execution of arbitrary JavaScript in the user's browser, potentially leading to session hijacking or other malicious actions.

Remediation

Users are advised to upgrade to version 0.16.10, where this vulnerability has been patched.

Added: Aug 2, 2025, 12:33 AM
Updated: Aug 2, 2025, 12:33 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.7
remediation
7.7
relevance
0.3
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.