CVE-2024-38289
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 40.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 40.61% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- rhubcom/turbomeeting
- Source
- cve@mitre.org
References
- https://github.com/google/security-research/security/advisories/GHSA-vx5j-8pgx-v42vExploit, Third Party Advisory
- https://www.rhubcom.com/v5/manuals.htmlProduct
- https://github.com/google/security-research/security/advisories/GHSA-vx5j-8pgx-v42vExploit, Third Party Advisory
- https://www.rhubcom.com/v5/manuals.htmlProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.