← Back

Turbomeeting

turbomeeting

Vendor: Rhubcom • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rhubcom
1Turbomeeting
Jun 17, 2026
Jul 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate...Show more
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.Show less
1Rhubcom
1Turbomeeting
Jun 17, 2026
Jul 25, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underly...Show more
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.Show less
1Rhubcom
1Turbomeeting
Jun 17, 2026
Jul 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random...Show more
The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value.Show less