Medium severity6.1NVD Advisory· Published Oct 21, 2020· Updated Jun 17, 2026
CVE-2020-27608
CVE-2020-27608
Description
In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*range: <2.2.28
- (no CPE)range: <2.2.28
- BigBlueButton/BigBlueButtondescription
Patches
Vulnerability mechanics
References
1- www.golem.de/news/big-blue-button-das-grosse-blaue-sicherheitsrisiko-2010-151610.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.