Impact
The vulnerability allows a HumHub Space administrator to inject arbitrary HTML or JavaScript into the comment‑deletion notification that is sent to the original comment author. When the author or other users view the notification, the injected code executes in their browser, enabling the attacker to hijack sessions, deface content, or deliver phishing payloads. The flaw is a stored cross‑site scripting condition, classified as CWE‑79.
Affected Systems
Affected products are HumHub 1.18.4, which runs on Linux, macOS, and Windows operating systems. Administrators of any Space using this version can exploit the flaw by deleting a comment and choosing to notify the author.
Risk and Exploitability
The CVSS score of 7.2 indicates a high impact. The EPSS score is 0.00367 (<1%), implying a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires local administrator privileges within the HumHub space; once achieved, the attacker can embed malicious code that runs in the browser context of users receiving the notification. The impact is limited to the affected users’ browsers and cannot affect the server or other users directly.
OpenCVE Enrichment