Unprotected CRUD Operations in Apache OpenMeetings: Denial of Service for Privileged Users

Unprotected CRUD Operations in Apache OpenMeetings: Denial of Service for Privileged Users

CVE-2018-1286 · MEDIUM Severity

AV:N/AC:L/AU:S/C:N/I:N/A:P

In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.

Learn more about our Cis Benchmark Audit For Apache Http Server.