SB2023033063 - User impersonation in Apache OpenMeetings
Published: March 30, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2023-28326)
The vulnerability allows a remote attacker to impersonate other users.
The vulnerability exists due to improper validation of the invitation URLs. A remote attacker can create a private room and impersonate any user invited to that room by manipulating the invitation URL.
Remediation
Install update from vendor's website.