CVE-2014-9528

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
06/01/2015
Last modified:
12/04/2025

Description

SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListController.php in HumHub 0.10.0-rc.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the from parameter to index.php. NOTE: this can be leveraged for cross-site scripting (XSS) attacks via a request that causes an error.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:humhub:humhub:*:rc1:*:*:*:*:*:* 0.10.0 (including)