{"id":"CVE-2021-43847","details":"HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.","aliases":["GHSA-f5hc-5wfr-7v74"],"modified":"2026-08-07T19:46:58.900737Z","published":"2021-12-20T22:15:08.003Z","references":[{"type":"ADVISORY","url":"https://github.com/humhub/humhub/releases/tag/v1.10.3"},{"type":"ADVISORY","url":"https://github.com/humhub/humhub/releases/tag/v1.9.3"},{"type":"FIX","url":"https://github.com/humhub/humhub/pull/5473"},{"type":"FIX","url":"https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/"},{"type":"EVIDENCE","url":"https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/humhub/humhub","events":[{"introduced":"0"},{"fixed":"6cf5a397a6b80e87e7b38a045475803a9f37496b"},{"introduced":"9441680ea372741a212741bfb70df4725bc8b04a"},{"fixed":"77052eb86baa4e264e102c53367529b506b864be"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.9.3"},{"introduced":"1.10.0"},{"fixed":"1.10.3"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:*"}}],"versions":["v1.10.2","v1.10.1","v1.10.0","v1.9.2","v1.9.1","v1.9.0","v1.9.0-beta.2","v1.8.0-beta.2","v1.8.0-beta.1","v1.6.4","v1.7.0","v1.6.3","v1.6.0","v1.6.2","v1.6.1","v1.6.0-beta.1","v1.5.0-beta.1","v1.4.0","v1.4.0-beta.2","v1.4.0-beta.1","v1.3.7","v1.3.6","v1.3.5","v1.3.4","v1.3.3","v1.3.2","v1.3.0","v1.3.0-beta.1","v1.2.1","v1.2.0-beta.4","v1.2.0-beta.2","v1.0.0-beta.2","v1.0.0-beta.1","v0.20.1","v0.20.0","v0.20.0-beta.1","v0.11.2","v0.11.1","v0.11.0","v0.9.0","v0.9.0-rc.2","v0.9.0-rc.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43847.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}