BigBlueButton

BigBlueButton

54 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 28.06.2024 21:15:03
  • Zuletzt bearbeitet 15.04.2026 00:35:42

BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. One of those ...

  • EPSS 0.42%
  • Veröffentlicht 30.10.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:24:48

BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe in...

  • EPSS 0.42%
  • Veröffentlicht 30.10.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:24:48

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions 2.6.12 and 2.7.0-rc.1 disabled...

  • EPSS 0.46%
  • Veröffentlicht 30.10.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:23:11

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other files without authentication, assu...

  • EPSS 0.54%
  • Veröffentlicht 30.10.2023 19:15:07
  • Zuletzt bearbeitet 21.11.2024 08:23:11

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does no...

  • EPSS 0.39%
  • Veröffentlicht 26.06.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:05:03

BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API request the user is able to supp...

  • EPSS 0.57%
  • Veröffentlicht 17.12.2022 01:15:09
  • Zuletzt bearbeitet 21.11.2024 06:48:39

BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Data. The moderators-only webcams lock setting is not enforced on the backend, which allows an attacker...

  • EPSS 0.44%
  • Veröffentlicht 16.12.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:48:40

BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant. Subscribing to the current-poll...

  • EPSS 0.55%
  • Veröffentlicht 16.12.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 07:24:09

BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll, and use this subscription to s...

  • EPSS 0.42%
  • Veröffentlicht 16.12.2022 14:15:09
  • Zuletzt bearbeitet 21.11.2024 07:24:09

BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds after their...