BigBlueButton

BigBlueButton

48 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht Exploit
  • EPSS 0.07%
  • Veröffentlicht 09.10.2025 20:40:04
  • Zuletzt bearbeitet 20.10.2025 15:36:03

BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for all participants in a meeting by sending a malformed `reactionEmo...

Medienbericht Exploit
  • EPSS 0.07%
  • Veröffentlicht 09.10.2025 20:29:25
  • Zuletzt bearbeitet 20.10.2025 15:33:21

BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's `Choices` response type. By sub...

Medienbericht
  • EPSS 0.04%
  • Veröffentlicht 09.10.2025 18:51:57
  • Zuletzt bearbeitet 20.10.2025 15:30:19

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XSS) vulnerability with the input location being the "Username" field and the output location on the "S...

  • EPSS 0.15%
  • Veröffentlicht 28.06.2024 21:15:03
  • Zuletzt bearbeitet 21.11.2024 09:27:25

BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the `/usr/local/bigbluebutton/core/vendor/bundle/ruby/2.7.0/gems/resque-2...

  • EPSS 0.09%
  • Veröffentlicht 28.06.2024 21:15:03
  • Zuletzt bearbeitet 21.11.2024 09:26:09

BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. One of those ...

  • EPSS 0.03%
  • Veröffentlicht 30.10.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:24:48

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions 2.6.12 and 2.7.0-rc.1 disabled...

  • EPSS 0.07%
  • Veröffentlicht 30.10.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:24:48

BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe in...

  • EPSS 0.24%
  • Veröffentlicht 30.10.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:23:11

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other files without authentication, assu...

  • EPSS 0.1%
  • Veröffentlicht 30.10.2023 19:15:07
  • Zuletzt bearbeitet 21.11.2024 08:23:11

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does no...

  • EPSS 0.09%
  • Veröffentlicht 26.06.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:05:03

BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API request the user is able to supp...