Medium severity6.5NVD Advisory· Published Apr 20, 2022· Updated Jun 17, 2026
CVE-2022-24865
CVE-2022-24865
Description
HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit eb83de20. It is recommended that the HumHub is upgraded to 1.11.0, 1.10.4 or 1.9.4. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/humhub/humhub/commit/eb83de20aaecc559ab77a44a6179646a99607e33nvdPatchThird Party Advisory
- huntr.dev/bounties/89d996a2-de30-4261-8e3f-98e54cb25f76/nvdExploitPatchThird Party Advisory
- github.com/humhub/humhub/security/advisories/GHSA-2h35-f226-3f57nvdThird Party Advisory
News mentions
0No linked articles in our index yet.