Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2090 | Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end. |
Github GHSA |
GHSA-335g-xcjh-ghc2 | Apache OpenMeetings vulnerable to SQL injection |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| http://markmail.org/message/j774dp5ro5xmkmg6 |
|
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T18:39:15.972Z
Reserved: 2017-04-11T00:00:00
Link: CVE-2017-7681
No data.
Status : Deferred
Published: 2017-07-17T13:18:29.877
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-7681
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA