VYPR

Bigbluebutton

by Bigbluebutton

Source repositories

CVEs (58)

  • CVE-2023-42803MedOct 30, 2023
    risk 0.00cvss 5.3epss 0.01

    BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of…

  • CVE-2023-33176MedJun 26, 2023
    risk 0.00cvss 4.8epss 0.00

    BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API request the user is able to supply a URL from which the…

  • CVE-2020-27602CriSep 29, 2022
    risk 0.00cvss 9.8epss 0.01

    BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

  • CVE-2020-27601LowSep 29, 2022
    risk 0.00cvss 3.5epss 0.01

    In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js.

  • CVE-2022-31065MedJun 27, 2022
    risk 0.00cvss 6.5epss 0.01

    BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript),…

  • CVE-2022-31064MedJun 27, 2022
    risk 0.00cvss 6.5epss 0.01

    BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the…

  • CVE-2022-29236MedJun 2, 2022
    risk 0.00cvss 4.3epss 0.01

    BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a…

  • CVE-2022-29235MedJun 2, 2022
    risk 0.00cvss 5.3epss 0.01

    BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the…

  • CVE-2022-29234MedJun 2, 2022
    risk 0.00cvss 4.3epss 0.01

    BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a…

  • CVE-2022-29233MedJun 2, 2022
    risk 0.00cvss 4.3epss 0.01

    BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of…

  • CVE-2022-29232MedJun 1, 2022
    risk 0.00cvss 6.5epss 0.01

    BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from different meetings on the server. The attacker must be a…

  • CVE-2022-29169HigJun 1, 2022
    risk 0.00cvss 7.5epss 0.01

    BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a RegularExpression, an attacker can cause denial of service…

  • CVE-2021-4143MedJan 19, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.

  • CVE-2020-28954MedNov 19, 2020
    risk 0.00cvss 5.3epss 0.01

    web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.

  • CVE-2020-28953MedNov 19, 2020
    risk 0.00cvss 4.3epss 0.01

    In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.

  • CVE-2020-27611HigOct 21, 2020
    risk 0.00cvss 7.3epss 0.01

    BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.

  • CVE-2020-12443CriApr 29, 2020
    risk 0.00cvss 9.8epss 0.04

    BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence. This can be leveraged for privilege escalation via a directory traversal to…

  • CVE-2020-12113MedApr 23, 2020
    risk 0.00cvss 6.1epss 0.01

    BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.

Page 3 of 3