Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown
CVE-2020-29043
Disclosure Date: November 26, 2020 (last updated February 22, 2025)
An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.
0
Attacker Value
Unknown
CVE-2020-29042
Disclosure Date: November 26, 2020 (last updated February 22, 2025)
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.
0
Attacker Value
Unknown
CVE-2020-28954
Disclosure Date: November 19, 2020 (last updated February 22, 2025)
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.
0
Attacker Value
Unknown
CVE-2020-28953
Disclosure Date: November 19, 2020 (last updated November 28, 2024)
In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.
0
Attacker Value
Unknown
CVE-2020-27642
Disclosure Date: October 22, 2020 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
0
Attacker Value
Unknown
CVE-2020-27604
Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared secret in the bigbluebutton.properties file. With the API shared secret, an attacker can (for example) use api/join to join an arbitrary meeting regardless of its guestPolicy setting.
0
Attacker Value
Unknown
CVE-2020-27611
Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
0
Attacker Value
Unknown
CVE-2020-27605
Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schwache Sandbox."
0
Attacker Value
Unknown
CVE-2020-27609
Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data storage beyond what is authorized for a specific meeting topic or participant.
0
Attacker Value
Unknown
CVE-2020-27603
Disclosure Date: October 21, 2020 (last updated November 28, 2024)
BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.
0