BigBlueButton
cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*
- <= 3.0.23
A vulnerability in BigBlueButton, an open-source virtual classroom platform, exists in versions prior to 3.0.24. The issue stems from a missing authorization that enables viewers to inject or overwrite captions. In version 3.0.24, permissions were tightened to restrict who can submit captions. Without this fix, viewers or non-audio users could alter caption content.
Exploitation of this vulnerability allows for unauthorized injection of captions or overwriting of existing captions by viewers or non-audio users.
Users are advised to upgrade to BigBlueButton version 3.0.24 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.