← Back

CVE-2016-2164

nvd nist
Published: Apr 11, 2016Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checking the specified protocol handler, which allows remote attackers to read arbitrary files by attempting to upload a file.

Affected (1)

Products: Apache: Openmeetings
1 product
Openmeetings
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.1.0

References (8)

Timeline

No history available yet.