Impact
HumHub 1.18.5 is affected by a stored cross‑site scripting flaw that allows any user with the delegated non‑system‑administrator Manage Users permission to inject persistent HTML or JavaScript into a Profile Field Category title. The injected code is rendered whenever the category is displayed, giving the attacker the ability to steal credentials or hijack sessions, especially if system administrators view the compromised page. This is a classic CWE‑79 injection weakness that compromises confidentiality and integrity of data viewed by other users.
Affected Systems
HumHub version 1.18.5 on Linux, macOS, and Windows operating systems is vulnerable. No other versions are listed as affected.
Risk and Exploitability
The CVSS score of 7.2 indicates a medium severity vulnerability, but the risk is higher if an attacker obtains the Manage Users privilege, which allows arbitrary script injection. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the web interface; any authenticated user with the limited administrative role can exploit the flaw by using the form that renders the profile field category title.
OpenCVE Enrichment