CVE-2025-61602
- EPSS 0.07%
- Veröffentlicht 09.10.2025 20:40:04
- Zuletzt bearbeitet 20.10.2025 15:36:03
BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for all participants in a meeting by sending a malformed `reactionEmo...
CVE-2025-61601
- EPSS 0.07%
- Veröffentlicht 09.10.2025 20:29:25
- Zuletzt bearbeitet 20.10.2025 15:33:21
BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's `Choices` response type. By sub...
CVE-2025-55200
- EPSS 0.04%
- Veröffentlicht 09.10.2025 18:51:57
- Zuletzt bearbeitet 20.10.2025 15:30:19
BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XSS) vulnerability with the input location being the "Username" field and the output location on the "S...
CVE-2024-39302
- EPSS 0.15%
- Veröffentlicht 28.06.2024 21:15:03
- Zuletzt bearbeitet 21.11.2024 09:27:25
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the `/usr/local/bigbluebutton/core/vendor/bundle/ruby/2.7.0/gems/resque-2...
CVE-2024-38518
- EPSS 0.09%
- Veröffentlicht 28.06.2024 21:15:03
- Zuletzt bearbeitet 21.11.2024 09:26:09
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. One of those ...
CVE-2023-43798
- EPSS 0.03%
- Veröffentlicht 30.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:24:48
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions 2.6.12 and 2.7.0-rc.1 disabled...
CVE-2023-43797
- EPSS 0.07%
- Veröffentlicht 30.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:24:48
BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe in...
CVE-2023-42804
- EPSS 0.24%
- Veröffentlicht 30.10.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:23:11
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other files without authentication, assu...
CVE-2023-42803
- EPSS 0.1%
- Veröffentlicht 30.10.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 08:23:11
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does no...
CVE-2023-33176
- EPSS 0.09%
- Veröffentlicht 26.06.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:05:03
BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API request the user is able to supp...