CVE-2017-7681
Apache OpenMeetings vulnerable to SQL injection
8.8
HIGH
CVSS 3.1
EPSS 1.3%
Description
Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end. The issue is fixed in version 3.3.0.
How to fix CVE-2017-7681
To remediate CVE-2017-7681, upgrade the affected package to a fixed version below.
- —upgrade to 3.3.0 or later
Is CVE-2017-7681 being exploited?
Low — EPSS is 1.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 1.0.0, < 3.3.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |