CVE-2023-28326: Apache OpenMeetings: allows user impersonation
Published Mar 28, 2023
·Updated
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0
Description: Attacker can elevate their privileges in any room
Affected Software
1 affected component
Apache OpenMeetings>=2.0<7.0.0
Event History
Mar 28, 2023
CVE Published
via MITRE·12:36 PM
Data Sourced
via MITRE·12:36 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28326?
CVE-2023-28326 has a high severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2023-28326?
To remediate CVE-2023-28326, upgrade Apache OpenMeetings to version 7.0.0 or later.
3
What vulnerability does CVE-2023-28326 exploit?
CVE-2023-28326 exploits a flaw that allows attackers to elevate their privileges in any room.
4
Which versions of Apache OpenMeetings are affected by CVE-2023-28326?
Apache OpenMeetings versions from 2.0.0 to before 7.0.0 are affected by CVE-2023-28326.
5
Who is responsible for the CVE-2023-28326 vulnerability?
The Apache Software Foundation is responsible for addressing CVE-2023-28326 within the affected versions of OpenMeetings.