Description
The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user passwords by leveraging knowledge of a user name and the current system time.
References (5)
Core 5
Core References
Various Sources x_refsource_misc
http://haxx.ml/post/141655340521/all-your-meetings-are-belong-to-us-remote-code
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/136432/Apache-OpenMeetings-3.1.0-MD5-Hashing.html
Various Sources x_refsource_confirm
https://www.apache.org/dist/openmeetings/3.1.1/CHANGELOG
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/537886/100/0/threaded
Patch, Vendor Advisory x_refsource_confirm
http://openmeetings.apache.org/security.html
Scores
CVSS v3
7.5
EPSS
0.0092
EPSS Percentile
76.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (1)
apache/openmeetings
< 3.1.0
Published
Apr 11, 2016
Tracked Since
Feb 18, 2026