← Back to browse · API

CVE-2024-38289

Severity
CRITICAL
CVSS
9.8
EPSS
0.40874
Risk score
53.51
CISA KEV
No
PoC
No
Published
2024-07-25
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-37249
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-37249

Description

A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.

References