CVE-2023-42804

CVSS V2 None CVSS V3 None
Description
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other files without authentication, assuming the files have certain extensions (txt, swf, svg, png). In version 2.6.0-beta.1, input validation was added on the parameters being passed and dangerous characters are stripped. There are no known workarounds.
Overview
  • CVE ID
  • CVE-2023-42804
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-10-30T18:14:41.419Z
  • Last Modified Date
  • 2023-10-30T18:14:41.419Z
History
Created Old Value New Value Data Type Notes
2024-06-25 13:57:26 Added to TrackCVE