Critical9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

PT-2024-62: SQL Injection in Vinteo Videoconferencing Server

Error type:

  • CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Vulnerability vector:

  • Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Severity (CVSSv3.1): 9.8 (critical)
  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • Severity (CVSSv4.0): 9.3 (critical)

Description:

The vulnerability was identified in Vinteo Videoconferencing Server, version 29.2.18.

The discovered vulnerability can be exploited by an authorized attacker to execute arbitrary SQL queries, which can lead to the possibility of executing arbitrary commands with superuser rights.

Vulnerability status: Confirmed by vendor

Recommendations:

  • Update to version v29.3.6 or higher

Researcher: Andrey Tyulenev (Positive Technologies)

Identifiers:

BDU:2024-08421

Vendor:

Vinteo

Vulnerable product:

Vinteo Videoconferencing Server

Vulnerable versions:

v29.2.18