CVE-2023-29246

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
12/05/2023
Last modified:
11/10/2024

Description

An attacker who has gained access to an admin account can perform RCE via null-byte injection<br /> <br /> Vendor: The Apache Software Foundation<br /> <br /> Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:* 2.0.0 (including) 7.1.0 (excluding)


References to Advisories, Solutions, and Tools