Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow non-member users to create new folders, up- and download files as a ZIP archive in public spaces. Private spaces are not affected. This issue has been patched in versions 0.16.11 and 0.17.2.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 28 Nov 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Humhub
Humhub files
Vendors & Products Humhub
Humhub files

Wed, 26 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Nov 2025 23:45:00 +0000

Type Values Removed Values Added
Description Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow non-member users to create new folders, up- and download files as a ZIP archive in public spaces. Private spaces are not affected. This issue has been patched in versions 0.16.11 and 0.17.2.
Title CFiles Unauthorized Folder/ZIP Access in Public Spaces
Weaknesses CWE-284
CWE-285
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-26T16:13:16.288Z

Reserved: 2025-11-18T16:14:56.694Z

Link: CVE-2025-65963

cve-icon Vulnrichment

Updated: 2025-11-26T16:13:13.399Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-26T00:15:51.100

Modified: 2025-12-01T15:39:53.100

Link: CVE-2025-65963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-28T08:51:30Z

Weaknesses