Description
An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
Remediation
References
https://lists.apache.org/thread/230plvhbdx26m43b0sy942wlwt6kkmmr
Related Vulnerabilities
CVE-2021-27906 Vulnerability in maven package org.apache.pdfbox:pdfbox
CVE-2016-3092 Vulnerability in maven package commons-fileupload:commons-fileupload
CVE-2020-6831 Vulnerability in maven package org.webjars.npm:electron
CVE-2016-2402 Vulnerability in maven package com.squareup.okhttp:okhttp
CVE-2022-43418 Vulnerability in maven package org.jenkins-ci.plugins:katalon