CVE-2017-7681
Estado: ModificadaAlta (8.8)—
Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.29%
- Percentil entre todas las CVEs puntuadas: 69
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-89
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-7681",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@apache.org",
"affectedData": [
{
"vendor": "Apache Software Foundation",
"product": "Apache OpenMeetings",
"versions": [
{
"status": "affected",
"version": "1.0.0"
}
]
}
]
}
],
"published": "2017-07-17T13:18:29.877",
"references": [
{
"url": "http://markmail.org/message/j774dp5ro5xmkmg6",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "security@apache.org"
},
{
"url": "http://markmail.org/message/j774dp5ro5xmkmg6",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end."
},
{
"lang": "es",
"value": "Apache OpenMeetings versión 1.0.0.0, es vulnerable a la inyección SQL. Esto permite a usuarios identificados modificar la estructura de la consulta existente y filtrar la estructura de otras consultas que están siendo realizadas por la aplicación en el back-end."
}
],
"lastModified": "2026-06-17T01:24:58.510",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:openmeetings:1.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72B6167B-E822-4146-87F2-E2769DC85F99"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8CDA54EE-9AE1-4551-8C24-D2077515029C"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB137AFF-1BB8-4FFC-9247-376718AAFEB2"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:2.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E8B4E9B-D707-4B96-93B0-7E5F19C8C9A9"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:2.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E44AAC6C-13E1-423B-BB4C-4C92B763DE34"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "268D5F6C-F1E8-400B-8D79-A79A9481DFDE"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57895052-DBEF-4CD4-B2B8-C6EBB7A607C8"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA80F112-8C3B-4D79-86A6-C7B3396C4DDB"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5AC28AE2-7EDD-4554-B418-7C4AD5D6E943"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "94BB2711-23CA-4FA5-8868-664A839F7EAA"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FCA799EE-CDF8-41C6-A3CF-5FC47ED0920C"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "96D13854-BD10-4404-89A7-F6D398680628"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3EC465AB-5CA6-4C97-8544-59D3236A7123"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1FCC94CB-EBC7-46D2-BD9E-DB043A4CD5B1"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC811824-EA8F-49F6-B732-10731A1BC0EF"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8AFF29DC-46BA-4505-A921-42C783BC4C8F"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "085A80B3-B880-428D-AF1D-BED61C31E304"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46036494-F97D-4C02-A630-102D9E7DE2CE"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2C208B6-E86A-4F73-B078-BA47BA1B162D"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "331EDEB7-D823-43C6-9D8B-E872F921A328"
},
{
"criteria": "cpe:2.3:a:apache:openmeetings:3.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B8D44A5F-C7BD-4CC2-9065-179FA92301C9"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@apache.org"
}