BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of validation failures. BigBlueButton 2.6.0-beta.2 contains a patch. There are no known workarounds.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-30T18:11:35.630Z
Updated: 2024-09-06T20:12:00.883Z
Reserved: 2023-09-14T16:13:33.306Z
Link: CVE-2023-42803
Vulnrichment
Updated: 2024-08-02T19:30:24.327Z
NVD
Status : Modified
Published: 2023-10-30T19:15:07.963
Modified: 2024-11-21T08:23:11.353
Link: CVE-2023-42803
Redhat
No data.