A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in file/file/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing a JavaScript payload in the filename parameter is echoed back, which resulted in reflected XSS.
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:humhub:humhub:1.3.10:*:*:*:community:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.3.10"
}
]
}