BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe innerHTML. Text sanitizing was added for lobby messages starting in versions 2.6.11 and 2.7.0-beta.3. There are no known workarounds.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-30T22:18:11.821Z
Updated: 2024-09-05T20:20:01.467Z
Reserved: 2023-09-22T14:51:42.339Z
Link: CVE-2023-43797
Vulnrichment
Updated: 2024-08-02T19:52:11.375Z
NVD
Status : Modified
Published: 2023-10-30T23:15:08.317
Modified: 2024-11-21T08:24:48.270
Link: CVE-2023-43797
Redhat
No data.