CVE 5.1 MEDIUM

Files is Vulnerable to Reflected Self-XSS through its File Move Functionality_CVE-2025-54789

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functionality does not contain logic that prevents injection of arbitrary JavaScript, which can lead to Browser JS code execution in the context of the user’s session. This is fixed in version 0.16.10.

Basic Information

ID CVE-2025-54789
Source GitHub_M
Published Aug 1, 2025 at 23:26
Modified Aug 4, 2025 at 15:40

Affected Product

Vendor humhub
Product cfiles
Version < 0.6.10
Affected Versions humhub cfiles < 0.6.10

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.