Medium severity6.3NVD Advisory· Published Oct 30, 2023· Updated Jun 17, 2026
CVE-2023-43797
CVE-2023-43797
Description
BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe innerHTML. Text sanitizing was added for lobby messages starting in versions 2.6.11 and 2.7.0-beta.3. There are no known workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*range: <2.6.11
- cpe:2.3:a:bigbluebutton:bigbluebutton:2.7.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:bigbluebutton:bigbluebutton:2.7.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:bigbluebutton:bigbluebutton:2.7.0:alpha3:*:*:*:*:*:*
- cpe:2.3:a:bigbluebutton:bigbluebutton:2.7.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:bigbluebutton:bigbluebutton:2.7.0:beta2:*:*:*:*:*:*
- (no CPE)range: <2.6.11, <2.7.0-beta.3
- (no CPE)range: < 2.6.11
Patches
Vulnerability mechanics
References
3- github.com/bigbluebutton/bigbluebutton/commit/304bc851a00558f99a908880f4ac44234a074c9dnvdPatchThird Party Advisory
- github.com/bigbluebutton/bigbluebutton/pull/18392nvdThird Party Advisory
- github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-v6wg-q866-h73xnvdThird Party Advisory
News mentions
0No linked articles in our index yet.