Humhub CFiles SQL Injection Vulnerability Allowing Unauthorized Data Access

Vulnerability

A SQL injection vulnerability has been identified in the Humhub CFiles module, specifically in versions prior to 0.16.10. The issue arises from a lack of proper validation in backend SQL queries, which could be exploited to access unauthorized data. This vulnerability has been classified as critical.

Impact

Exploitation of this vulnerability could lead to unauthorized access to data by manipulating backend SQL queries.

Remediation

Users are advised to update to version 0.16.10 or later, where this vulnerability has been fixed.

Added: Aug 2, 2025, 12:31 AM
Updated: Aug 2, 2025, 12:31 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.