CVE-2017-7666: CSRF
Published Jul 14, 2017
·Updated
Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.
Affected Software
21 affected components
Apache OpenMeetings=1.0.0
Apache OpenMeetings=2.0
Apache OpenMeetings=2.1
Apache OpenMeetings=2.1.1
Apache OpenMeetings=2.2.0
Apache OpenMeetings=3.0.0
Apache OpenMeetings=3.0.1
Apache OpenMeetings=3.0.2
Apache OpenMeetings=3.0.3
Apache OpenMeetings=3.0.4
Apache OpenMeetings=3.0.5
Apache OpenMeetings=3.0.6
Apache OpenMeetings=3.0.7
Apache OpenMeetings=3.1.0
Apache OpenMeetings=3.1.1
Apache OpenMeetings=3.1.2
Apache OpenMeetings=3.1.3
Apache OpenMeetings=3.1.4
Apache OpenMeetings=3.1.5
Apache OpenMeetings=3.2.0
Apache OpenMeetings=3.2.1
Event History
Jul 14, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7666?
CVE-2017-7666 is considered a critical vulnerability due to its exploitation potential through multiple attack vectors including CSRF and XSS.
2
How do I fix CVE-2017-7666?
To fix CVE-2017-7666, update Apache OpenMeetings to version 3.2.1 or later.
3
What types of attacks are associated with CVE-2017-7666?
CVE-2017-7666 is associated with Cross-Site Request Forgery (CSRF), Cross-Site Scripting (XSS), click-jacking, and MIME-based attacks.
4
Which versions of Apache OpenMeetings are affected by CVE-2017-7666?
Apache OpenMeetings versions 1.0.0 through 3.1.5 are affected by CVE-2017-7666.
5
What should users of Apache OpenMeetings do regarding CVE-2017-7666?
Users of Apache OpenMeetings should immediately upgrade to a patched version to mitigate the risks associated with CVE-2017-7666.