← Back to CVE List

CVE-2024-38289

Published: 2024-07-25T20:15Z
Last Modified: 2024-11-21T09:25Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt