CVE-2019-13409: Topmeeting
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password.
Affected products
- Topmeeting Topmeeting: before 8.8 (fixed in 8.8)
Published 2019-10-17. Last modified 2026-06-17.