Impact
A missing authorization check in HumHub’s Space member management controller allows any authenticated user, regardless of role or membership, to trigger the removal of all members from any space. In affected versions 1.13.0 through 1.18.2, this results in the total loss of access for all space members and can disrupt collaboration, effectively causing a denial of service for the space. The weakness is identified as CWE‑862 (Missing Authorization).
Affected Systems
HumHub, the open‑source enterprise social network, is affected in all releases from version 1.13.0 through 1.18.2 inclusive. Version 1.18.3 and later contain the fix and are therefore safe.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity with moderate impact. The EPSS score of < 1% suggests that, at present, the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only an authenticated session; no additional privileges or remote code execution capabilities are necessary. The attacking user, making the threat only contingent on account compromise or insider misuse.
OpenCVE Enrichment