CVE-2019-13409: Topmeeting

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password.

Affected products

Published 2019-10-17. Last modified 2026-06-17.