CVE-2024-38287 Information

Description

The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator’s password to a random insecure 8-digit value.

Reference

https://www.rhubcom.com/v5/manuals.html https://github.com/google/security-research/security/advisories/GHSA-c84v-4pjw-4mh2

Share on: