Podatność CVE-2022-31064


Publikacja: 2022-06-27

Opis:
BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the JavaScript will be executed. This issue has been addressed in version 2.4.8 and 2.5.0. There are no known workarounds for this issue.

W naszej bazie, znaleźliśmy następujące noty dla tego CVE:
Tytuł
Autor
Data
Low
BigBlueButton 2.3 / 2.4.7 Cross Site Scripting
Rick Verdoes
02.07.2022

Typ:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 Referencje:
https://pentests.nl/pentest-blog/stored-xss-in-bigbluebutton/
https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-hwv2-5pf5-hr87
https://github.com/bigbluebutton/bigbluebutton/pull/15067
https://github.com/bigbluebutton/bigbluebutton/pull/15090

Copyright 2024, cxsecurity.com

 

Back to Top