Filtered by vendor Bigbluebutton Subscriptions
Total 47 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-27609 1 Bigbluebutton 1 Bigbluebutton 2020-10-29 5.3 Medium
BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data storage beyond what is authorized for a specific meeting topic or participant.
CVE-2020-27612 1 Bigbluebutton 1 Bigbluebutton 2020-10-29 4.3 Medium
Greenlight in BigBlueButton through 2.2.28 places usernames in room URLs, which may represent an unintended information leak to users in a room, or an information leak to outsiders if any user publishes a screenshot of a browser window.
CVE-2020-27613 1 Bigbluebutton 1 Bigbluebutton 2020-10-29 8.4 High
The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access.
CVE-2020-27642 1 Bigbluebutton 1 Greenlight 2020-10-27 6.1 Medium
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
CVE-2020-26163 1 Bigbluebutton 1 Greenlight 2020-10-15 8.8 High
BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.
CVE-2020-12113 1 Bigbluebutton 1 Bigbluebutton 2020-09-30 6.1 Medium
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
CVE-2020-12443 1 Bigbluebutton 1 Bigbluebutton 2020-05-06 9.8 Critical
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence. This can be leveraged for privilege escalation via a directory traversal to bigbluebutton.properties. NOTE: this issue exists because of an ineffective mitigation to CVE-2020-12112 in which there was an attempted fix within an NGINX configuration file, without considering that the relevant part of NGINX is case-insensitive.