PT-2025-41453 · Unknown · Bigbluebutton
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
BigBlueButton versions prior to 3.0.13
Description
BigBlueButton, an open-source virtual classroom, has a Stored Cross-Site Scripting (XSS) issue in the "Shared Notes" feature. The input location for this issue is the
Username field, and the output is displayed on the "Shared Notes" page when a user with a malicious username edits content. This allows a low-privileged user to execute arbitrary JavaScript in the context of higher-privileged users, such as Admins, who open the "Shared Notes" page.Recommendations
Update to BigBlueButton version 3.0.13 or later.
Exploit
Fix
DoS
XSS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bigbluebutton