Humhub CFiles SQL Injection Vulnerability Allowing Unauthorized Data Access
Vulnerability
A SQL injection vulnerability has been identified in the Humhub CFiles module, specifically in versions prior to 0.16.10. The issue arises from a lack of proper validation in backend SQL queries, which could be exploited to access unauthorized data. This vulnerability has been classified as critical.
Impact
Exploitation of this vulnerability could lead to unauthorized access to data by manipulating backend SQL queries.
Remediation
Users are advised to update to version 0.16.10 or later, where this vulnerability has been fixed.
Added: Aug 2, 2025, 12:31 AM
Updated: Aug 2, 2025, 12:31 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
7.4remediation
7.7relevance
0.3threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
