Beveiligingsadvies

CVE-2023-43797

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-10-30 22:18:11
Laatst bijgewerkt 2024-09-05 20:20:01
Toegewezen door GitHub_M
CVSS-score 6.3
Status PUBLISHED

Beschrijving

BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe innerHTML. Text sanitizing was added for lobby messages starting in versions 2.6.11 and 2.7.0-beta.3. There are no known workarounds.