CVE-2017-7681

HIGH

Apache OpenMeetings 1.0.0 - SQL Injection

Title source: llm
STIX 2.1

Description

Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end.

References (1)

Core 1
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://markmail.org/message/j774dp5ro5xmkmg6

Scores

CVSS v3 8.8
EPSS 0.0010
EPSS Percentile 26.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (23)
apache/openmeetings 1.0.0
apache/openmeetings 2.0
apache/openmeetings 2.1
apache/openmeetings 2.1.1
apache/openmeetings 2.2.0
apache/openmeetings 3.0.0
apache/openmeetings 3.0.1
apache/openmeetings 3.0.2
apache/openmeetings 3.0.3
apache/openmeetings 3.0.4
... and 13 more
Published Jul 17, 2017
Tracked Since Feb 18, 2026