Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the exploitation of backend SQL queries without direct output, potentially allowing unauthorized data access. This is fixed in version 0.16.10.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:humhub:files:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 05 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Humhub
Humhub files |
|
| Vendors & Products |
Humhub
Humhub files |
Mon, 04 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 02 Aug 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the exploitation of backend SQL queries without direct output, potentially allowing unauthorized data access. This is fixed in version 0.16.10. | |
| Title | Files: Potential for SQL Injection through File Browse and List Operations | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-01T23:37:23.353Z
Updated: 2025-08-04T15:22:29.986Z
Reserved: 2025-07-29T16:50:28.393Z
Link: CVE-2025-54790
Updated: 2025-08-04T15:22:27.202Z
Status : Analyzed
Published: 2025-08-02T00:15:26.360
Modified: 2025-09-12T16:32:36.493
Link: CVE-2025-54790
No data.