Record summary

CVE-2024-38288 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 26, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListBefore 8.0affected

Nuclei templates

1
ProjectDiscoveryHIGHTurboMeeting - Post-Authentication Command Injection

The Certificate Signing Request (CSR) feature in the admin portal of the application is vulnerable to command injection. This vulnerability could allow authenticated admin users to execute arbitrary commands on the underlying server by injecting malicious input into the CSR generation process. The application failed to properly sanitize user-supplied input before using it in a command executed privileges.

Impact

Authenticated admin users can execute arbitrary OS commands on the TurboMeeting server through malicious CSR input, leading to complete system compromise and potential access to all meeting data.

Remediation

Upgrade to the latest patched version of RHUB TurboMeeting or apply vendor-provided security updates.

Authorsrootxharsh, iamnoooob, pdresearch
Template tagscvecve2024rceturbomeetingauthenticatedvuln
CPE: cpe:2.3:a:rhubcom:turbomeeting:*:*:*:*:*:*:*:*
Shodan: html:"TurboMeeting"

Source: ProjectDiscovery

References

2