cve/2024/CVE-2024-38289.md
2025-09-29 16:08:36 +00:00

775 B

CVE-2024-38289

Description

A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.

POC

Reference

Github