CVE-2024-38289
rhubcom turbomeeting Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2024-38289 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 14, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
turbomeetingBrowse r-hub / turbomeetingDefault status: unknown | CVE List | Before 8.x | affected |
turbomeetingBrowse rhubcom / turbomeeting | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALTurboMeeting - Boolean-based SQL Injection
A Boolean-based SQL injection vulnerability in the "RHUB TurboMeeting" web application. This vulnerability could allow an attacker to execute arbitrary SQL commands on the database server, potentially allowing them to access sensitive data or compromise the server.
Impact
Unauthenticated attackers can execute arbitrary SQL commands to extract sensitive data including user credentials, meeting information, and potentially compromise the entire TurboMeeting database.
Remediation
Upgrade to the latest patched version of RHUB TurboMeeting or apply vendor-provided security updates.
Source: ProjectDiscovery