CVE-2017-7681: Apache Openmeetings

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end.

Affected products

  • Apache Openmeetings: version 1.0.0 only; version 2.0 only; version 2.1 only; version 2.1.1 only; version 2.2.0 only; version 3.0.0 only; …

Published 2017-07-17. Last modified 2026-06-17.