Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown

CVE-2020-29043

Disclosure Date: November 26, 2020 (last updated February 22, 2025)
An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.
Attacker Value
Unknown

CVE-2020-29042

Disclosure Date: November 26, 2020 (last updated February 22, 2025)
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.
Attacker Value
Unknown

CVE-2020-28954

Disclosure Date: November 19, 2020 (last updated February 22, 2025)
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.
Attacker Value
Unknown

CVE-2020-28953

Disclosure Date: November 19, 2020 (last updated November 28, 2024)
In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.
Attacker Value
Unknown

CVE-2020-27642

Disclosure Date: October 22, 2020 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
Attacker Value
Unknown

CVE-2020-27604

Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared secret in the bigbluebutton.properties file. With the API shared secret, an attacker can (for example) use api/join to join an arbitrary meeting regardless of its guestPolicy setting.
Attacker Value
Unknown

CVE-2020-27611

Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
Attacker Value
Unknown

CVE-2020-27605

Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schwache Sandbox."
Attacker Value
Unknown

CVE-2020-27609

Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data storage beyond what is authorized for a specific meeting topic or participant.
Attacker Value
Unknown

CVE-2020-27603

Disclosure Date: October 21, 2020 (last updated November 28, 2024)
BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.