Apache OpenMeetings: allows null-byte Injection
CVE-2023-29246
7.2HIGH
What is CVE-2023-29246?
A critical vulnerability in Apache OpenMeetings allows attackers with admin access to exploit a null-byte injection, potentially leading to remote code execution. This situation poses a significant risk as it could allow unauthorized access to sensitive data and systems. Users must take immediate action to address this vulnerability by updating to the latest version to mitigate the risks associated with this flaw.
Affected Version(s)
Apache OpenMeetings 2.0.0 < 7.1.0