Insufficient Authorization in Humhub Files Module
CVE-2025-65963
5.4MEDIUM
What is CVE-2025-65963?
The Files module in Humhub, which facilitates file management within user profiles and spaces, contains a vulnerability that permits unauthorized users to create folders and manipulate files in public spaces. Users who are not members can upload and download files within ZIP archives, leading to potential unauthorized data exposure. Fortunately, this issue has been addressed and patched in versions 0.16.11 and 0.17.2, ensuring enhanced security for users.
Affected Version(s)
cfiles < 0.16.11 < 0.16.11
cfiles >= 0.17.0, < 0.17.2 < 0.17.0, 0.17.2
