Vulnerability CVE-2024-38289


Published: 2024-07-25

Description:
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.

 References:
https://www.rhubcom.com/v5/manuals.html
https://github.com/google/security-research/security/advisories/GHSA-vx5j-8pgx-v42v

Copyright 2026, cxsecurity.com

 

Back to Top