PT-2024-27927 · R Hub · R-Hub Turbomeeting
0Xc0Ffeee
·
Published
2024-07-25
·
Updated
2024-09-09
·
CVE-2024-38289
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
R-HUB TurboMeeting versions through 8.x
Description
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint allows unauthenticated remote attackers to extract hashed passwords from the database and authenticate to the application via crafted SQL input.
Recommendations
For R-HUB TurboMeeting versions through 8.x, consider restricting access to the Virtual Meeting Password endpoint until a patch is available.
As a temporary workaround, avoid using crafted SQL input in the VMP endpoint to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
R-Hub Turbomeeting