Vulnerability Description
Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Openmeetings | 1.0.0 |
Related Weaknesses (CWE)
References
- http://markmail.org/message/j774dp5ro5xmkmg6Mailing ListThird Party Advisory
- http://markmail.org/message/j774dp5ro5xmkmg6Mailing ListThird Party Advisory
FAQ
What is CVE-2017-7681?
CVE-2017-7681 is a vulnerability with a CVSS score of 8.8 (HIGH). Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the applic...
How severe is CVE-2017-7681?
CVE-2017-7681 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7681?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Openmeetings.