CVE-2024-38518
- EPSS 0.31%
- Veröffentlicht 28.06.2024 21:15:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. One of those ...
CVE-2023-43797
- EPSS 0.42%
- Veröffentlicht 30.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:24:48
BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe in...
CVE-2023-43798
- EPSS 0.42%
- Veröffentlicht 30.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:24:48
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions 2.6.12 and 2.7.0-rc.1 disabled...
CVE-2023-42804
- EPSS 0.46%
- Veröffentlicht 30.10.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:23:11
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other files without authentication, assu...
CVE-2023-42803
- EPSS 0.54%
- Veröffentlicht 30.10.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 08:23:11
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does no...
CVE-2023-33176
- EPSS 0.39%
- Veröffentlicht 26.06.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:05:03
BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API request the user is able to supp...
CVE-2022-23488
- EPSS 0.57%
- Veröffentlicht 17.12.2022 01:15:09
- Zuletzt bearbeitet 21.11.2024 06:48:39
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Data. The moderators-only webcams lock setting is not enforced on the backend, which allows an attacker...
CVE-2022-23490
- EPSS 0.44%
- Veröffentlicht 16.12.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:48:40
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant. Subscribing to the current-poll...
CVE-2022-41964
- EPSS 0.55%
- Veröffentlicht 16.12.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:24:09
BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll, and use this subscription to s...
CVE-2022-41963
- EPSS 0.42%
- Veröffentlicht 16.12.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 07:24:09
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds after their...