CVE-2019-12743: Humhub Social Network Kit

Medium severity, CVSS 5.3. EPSS: 1.5% chance of exploitation in the next 30 days.

HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response Discrepancy Information Exposure.

Affected products

  • Humhub Social Network Kit: version 1.3.13 only

Published 2019-07-29. Last modified 2026-06-17.