PT-2023-3158 · Apache · Apache Openmeetings
Stefan Schiller
·
Published
2023-05-12
·
Updated
2024-10-11
·
CVE-2023-28936
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache OpenMeetings versions 2.0.0 through 7.1.0
Description
The issue is related to insufficient comparison in the Apache OpenMeetings video conferencing software. Exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information.
Recommendations
For Apache OpenMeetings versions 2.0.0 through 7.1.0, update to a version after 7.1.0 to resolve the issue.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Openmeetings