CVE-2023-43797
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2023-43797 is a cross-site scripting (XSS) vulnerability affecting versions prior to 2.6.11 and 2.7.0-beta.3 of the open-source virtual classroom software, BigBlueButton. The Guest Lobby feature was found to be susceptible to XSS attacks due to the insertion of unsanitized messages into an element using unsafe innerHTML. This issue could potentially allow attackers to inject malicious scripts into unsuspecting users' browsers while they wait in the lobby to enter a meeting. A patch has been released in versions 2.6.11 and 2.7.0-beta.3, which include text sanitization for lobby messages to mitigate this vulnerability. Unfortunately, there are currently no known workarounds for affected users until they upgrade to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- BigBlueButton
- BigBlueButton BigBlueButton
Affected Vendors
- BigBlueButton Inc.