### [CVE-2024-38289](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38289) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input. ### POC #### Reference - https://github.com/google/security-research/security/advisories/GHSA-vx5j-8pgx-v42v #### Github - https://github.com/opendr-io/causality