← Back

CVE-2022-31064

nvd nist
Published: Jun 27, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the JavaScript will be executed. This issue has been addressed in version 2.4.8 and 2.5.0. There are no known workarounds for this issue.

Affected (15)

1 product
Bigbluebutton
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Bigbluebutton
From 2.4 to 2.4.8
Version 2.3.0
Version 2.4.9
Version 2.5 alpha1
Version 2.5 alpha2
Version 2.5 alpha3
Version 2.5 alpha4
Version 2.5 alpha5
Version 2.5 alpha6
Version 2.5 beta1
Version 2.5 beta2
Version 2.5 rc.1
Version 2.5 rc.2
Version 2.5 rc.3
Version 2.5 rc.4

References (12)

Source: security-advisories@github.com
ExploitThird Party AdvisoryVDB Entry
Source: security-advisories@github.com
ExploitMailing ListThird Party Advisory
Source: security-advisories@github.com
PatchRelease NotesThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.