CVE-2024-38289: Rhubcom Turbomeeting

Critical severity, CVSS 9.8. EPSS: 40.6% chance of exploitation in the next 30 days.

A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.

Affected products

  • Rhubcom Turbomeeting: up to and including 8.0

Published 2024-07-25. Last modified 2026-06-17.