Record summary

CVE-2024-38289 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 14, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListBefore 8.xaffected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALTurboMeeting - Boolean-based SQL Injection

A Boolean-based SQL injection vulnerability in the "RHUB TurboMeeting" web application. This vulnerability could allow an attacker to execute arbitrary SQL commands on the database server, potentially allowing them to access sensitive data or compromise the server.

Impact

Unauthenticated attackers can execute arbitrary SQL commands to extract sensitive data including user credentials, meeting information, and potentially compromise the entire TurboMeeting database.

Remediation

Upgrade to the latest patched version of RHUB TurboMeeting or apply vendor-provided security updates.

Authorsrootxharsh, iamnoooob, pdresearch
Template tagscvecve2024sqliturbomeetingvkevvuln
CPE: cpe:2.3:a:rhubcom:turbomeeting:*:*:*:*:*:*:*:*
Shodan: html:"TurboMeeting"

Source: ProjectDiscovery

References

2