CVE-2023-29246 Information

Description

An attacker who has gained access to an admin account can perform RCE via null-byte injection

Vendor: The Apache Software Foundation

Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0

Reference

https://lists.apache.org/thread/230plvhbdx26m43b0sy942wlwt6kkmmr

Share on: