High severity8.8NVD Advisory· Published Jul 17, 2017· Updated May 13, 2026
CVE-2017-7681
CVE-2017-7681
Description
Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.openmeetings:openmeetings-parentMaven | >= 1.0.0, < 3.3.0 | 3.3.0 |
Affected products
22cpe:2.3:a:apache:openmeetings:1.0.0:*:*:*:*:*:*:*+ 20 more
- cpe:2.3:a:apache:openmeetings:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openmeetings:3.2.1:*:*:*:*:*:*:*
- Apache Software Foundation/Apache OpenMeetingsv5Range: 1.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- markmail.org/message/j774dp5ro5xmkmg6nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-335g-xcjh-ghc2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-7681ghsaADVISORY
News mentions
0No linked articles in our index yet.