CVEs (49)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Jun 27, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the...Show more |
BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in...Show more |
BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could inject JavaScript payload in his/her username. The payload gets executed...Show more |
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Jun 2, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission che...Show more |
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Jun 2, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find info...Show more |
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Jun 2, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in th...Show more |
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Jun 2, 2022 N/A· v4 4.3 MEDIUM· v3 5.0 MEDIUM· v2 BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting t...Show more |
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Jun 1, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from...Show more |
BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a...Show more |
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Jan 19, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0. |
An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has...Show more |
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code. |
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Nov 19, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name. |
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Nov 19, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In BigBlueButton before 2.2.29, a user can vote more than once in a single poll. |
The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access. |
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Oct 21, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Greenlight in BigBlueButton through 2.2.28 places usernames in room URLs, which may represent an unintended information leak to users in a room, or an information leak to outsiders if any user publishes a screenshot of a...Show more |
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint. |
The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not automatically set up a firewall configuration to block external access. |
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Oct 21, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data storage beyond what is authorized for a specific meeting topic or participan...Show more |
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Oct 21, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document. |