A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 13 Aug 2024 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Rhubcom
Rhubcom turbomeeting
CPEs cpe:2.3:a:rhubcom:turbomeeting:*:*:*:*:*:*:*:*
Vendors & Products Rhubcom
Rhubcom turbomeeting

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T04:04:25.174Z

Reserved: 2024-06-13T00:00:00

Link: CVE-2024-38289

cve-icon Vulnrichment

Updated: 2024-07-31T13:57:30.345Z

cve-icon NVD

Status : Modified

Published: 2024-07-25T20:15:05.017

Modified: 2024-11-21T09:25:18.520

Link: CVE-2024-38289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.